Bug 2050728 (CVE-2022-0670)
Summary: | CVE-2022-0670 ceph: user/tenant can obtain access (read/write) to any share | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Pedro Sampaio <psampaio> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | amctagga, anharris, aoconnor, bniver, branto, danmick, david, dbecker, eglynn, fedora, flucifre, gcharot, gfarnum, gfidente, gmeno, hvyas, i, jdurgin, jjoyce, josef, jschluet, kkeithle, lhh, loic, lpeer, madam, mbenjamin, mburns, mgarciac, mhackett, mhicks, muagarwa, ocs-bugs, ramkrsna, sclewis, seamurph, security-response-team, slinaber, sostapov, spower, steve, vereddy, vimartin |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | RHCS 5.2 Ceph v 17.2.2 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in OpenStack Manila, where owning a Ceph File system "share" enables the owner to read/write any Manila share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This flaw allows an attacker to compromise the confidentiality and integrity of a file system.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-09-01 05:55:51 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2056107, 2056108, 2056109, 2065602, 2065603, 2110017 | ||
Bug Blocks: | 2050731 |
Description
Pedro Sampaio
2022-02-04 14:28:28 UTC
Removed OSD from affects. Created ceph tracking bugs for this issue: Affects: fedora-all [bug 2110017] FEDORA-2022-6d129f14f2 has been pushed to the Fedora 35 stable repository. If problem still persists, please make note of it in this bug report. This issue has been addressed in the following products: Red Hat Ceph Storage 5.2 Via RHSA-2022:5997 https://access.redhat.com/errata/RHSA-2022:5997 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-0670 |