Database/Control plane, storage & DevOps
Ceph MON (CephX authentication): The monitor does not sanitize other_keys when handling CEPHX_GET_AUTH_SESSION_KEY, so
Impact
The monitor does not sanitize other_keys when handling CEPHX_GET_AUTH_SESSION_KEY, so an attacker who has any CephX credential (or who can force one to be reissued) can reuse a key and authenticate as a different, higher-privileged Ceph entity. That is escalation from one tenant's cephx identity to another's, including admin-level access to pools they do not own.
Who can reach it
Anyone holding a valid CephX credential for the cluster and able to reach the monitors on the cluster/public network - which includes any tenant compute node that mounts RBD or CephFS natively.
What to do
Upgrade the monitors to Ceph 14.2.20 or later (and matching Octopus/Pacific builds), then restart ceph-mon. Rotate CephX keys afterwards, since anything issued before the fix could already have been reused. Keep the Ceph public network off tenant-routable paths.
References
Related entries
- AMD PSP1 Configuration Block (APCB) parsing: An out-of-bounds memory write while the platform processes the AMD PSP1CVE-2021-26344 · AMD PSP1 Configuration Block (APCB) parsingHigh
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpoint: Code injectionCVE-2023-25549 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - network settings endpointHigh
- Lenovo ThinkSystem SMM / SMM2 and FPC (command injection): An authenticated user with elevated privileges executesCVE-2024-2659 · Lenovo ThinkSystem SMM / SMM2 and FPC (command injection)High
- Schneider Electric Data Center Expert - upgrade bundle signature verification: Improper cryptographic signatureCVE-2024-8531 · Schneider Electric Data Center Expert - upgrade bundle signature verificationHigh
- HashiCorp Vault: Operator with write on the root namespace identity endpoint escalates self/others to the root policyCVE-2024-9180 · HashiCorp VaultHigh
- Palo Alto PAN-OS: Admin with mgmt-interface access performs firewall actions as rootCVE-2024-9474 · Palo Alto PAN-OSHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.