FlawAtlas
Search the atlas
SUSE-SU-2018:1920-1 Not scored

Security update for ceph

This update for ceph to version ceph-12.2.5-419-g8cbf63d997 fixes the following issues: - CVE-2018-10861: Ensure that ceph-mon does perform authorization on all OSD pool ops (bsc#1099162). - CVE-2018-1129: cephx signature check bypass (bsc#1096748). - CVE-2018-1128: cephx protocol was vulnerable to replay attack (bsc#1096748).

Exploit probability Not scored
Published July 10, 2018
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 5 ceph

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:1920-1

This update for ceph to version ceph-12.2.5-419-g8cbf63d997 fixes the following issues: - CVE-2018-10861: Ensure that ceph-mon does perform authorization on all OSD pool ops (bsc#1099162). - CVE-2018-1129: cephx signature check bypass (bsc#1096748). - CVE-2018-1128: cephx protocol was vulnerable to replay attack (bsc#1096748).

View original source

05 / REFERENCES

Further evidence