Database/Control plane, storage & DevOps
Ceph MON / MGR (ceph-mon, ceph-mgr): Ceph-mon and ceph-mgr fail to enforce the caps on an authenticated principal, so a
Impact
Ceph-mon and ceph-mgr fail to enforce the caps on an authenticated principal, so a low-privileged CephX user reaches admin-only commands. From there the attacker can read and change cluster configuration, create or delete pools and effectively take ownership of storage belonging to other tenants.
Who can reach it
Any authenticated CephX principal that can reach the mon or mgr on the Ceph public network, including tenant nodes that hold only a restricted client key.
What to do
Upgrade to Ceph 15.2.2 or later and restart ceph-mon and ceph-mgr. Audit the caps on every CephX principal afterwards and revoke any that were widened. Never expose mon/mgr ports to tenant-routable networks.
References
Related entries
- Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.js: Unauthenticated arbitrary file deletionCVE-2021-23279 · Eaton Intelligent Power Manager (IPM) prior to 1.69 - meta_driver_srv.jsHigh
- Intel Data Center Manager: Improper neutralisation (injection) in Data Center Manager lets an authenticated userCVE-2022-21225 · Intel Data Center ManagerHigh
- Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storage: DCE stores device passwordsCVE-2022-32519 · Schneider Electric Data Center Expert (versions prior to v7.9.0) - credential storageHigh
- Intel Neural Compressor (SQL injection): SQL injection reachable by an authenticated user of Neural CompressorCVE-2024-39368 · Intel Neural Compressor (SQL injection)High
- Dell OpenManage Enterprise (code injection): A low-privileged remote user injects code into OME and executesCVE-2024-45766 · Dell OpenManage Enterprise (code injection)High
- Linux NFS server (nfsd, NFSv4 file creation ACL): When a client sets an ACL during NFSv4 file creation, nfsd silentlyCVE-2025-68803 · Linux NFS server (nfsd, NFSv4 file creation ACL)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.