Database/Control plane, storage & DevOps
Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitrary
Impact
An unauthenticated HTTP request with traversal sequences reads arbitrary files off the manager node. On a real cluster that means pulling /etc/ceph/ceph.client.admin.keyring and taking full administrative control of all storage, so it is effectively a pre-auth path to cluster admin.
Who can reach it
Anyone who can reach the dashboard's HTTP port. Dashboards are frequently left reachable from the management or tenant VLAN, which is what makes this severe.
What to do
Upgrade ceph-mgr to 14.2.7 / 15.1.0 or later and restart the mgr. Assume the admin keyring leaked and rotate it. Bind the dashboard to a management-only interface behind authentication rather than exposing it on a shared network.
References
Related entries
- IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendCVE-2020-5015 · IBM Elastic Storage System / Elastic Storage Server (UDP request handling)High
- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingCVE-2021-27005 · NetApp Clustered Data ONTAP httpdHigh
- SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedCVE-2021-28361 · SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01)High
- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/CVE-2021-43798 · GrafanaHigh
- Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05CVE-2021-45454 · Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 - power telemetry exposed through the Linux HWmon interfaceHigh
- Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi): Unauthenticated arbitrary file read off the gatewayCVE-2022-37122 · Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.