Database/Control plane, storage & DevOps
Ceph Manager (volumes plugin): Owner of one CephFS share can read/write any share or the entire file system
CVSS 9.1CVE-2022-0670Control plane, storage & DevOpscurated
Impact
Owner of one CephFS share can read/write any share or the entire file system - cross-tenant
Who can reach it
Network (remote)
What to do
Data-plane: ceph-mgr upgrade across the cluster; audit CephFS share access
References
Related entries
- Zabbix: Unverified user login in session data (SAML SSO enabled)CVE-2022-23131 · ZabbixCritical
- FlyteConsole (cors_proxy endpoint): FlyteConsole's cors_proxy forwards attacker-chosen URLs, so anyone who reaches theCVE-2022-24856 · FlyteConsole (cors_proxy endpoint)Critical
- CyberPower PowerPanel Business - default.cmd file upload: Unrestricted upload of a dangerous file type into default.cmdCVE-2023-25132 · CyberPower PowerPanel Business - default.cmd file uploadCritical
- HAProxy (before 2.7.3): HAProxy's HTTP/1 header parser accepts empty header field names, which can be used to makeCVE-2023-25725 · HAProxy (before 2.7.3)Critical
- DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation): A deviceCVE-2023-31127 · DMTF libspdm - SPDM session establishment (reference implementation used in GPU/device attestation)Critical
- Samba: Path traversal in client pipe namesCVE-2023-3961 · SambaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.