Nonce Reuse Vulnerability in Red Hat Ceph Storage and Openshift Container Storage
CVE-2020-1759
6.4MEDIUM
What is CVE-2020-1759?
A nonce reuse vulnerability has been identified in the secure mode of the messenger v2 protocol utilized by Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2. This security flaw enables an attacker to exploit the reuse of nonce values within a single session, potentially allowing them to forge authentication tags. As a result, messages that rely on reused nonce values are at risk for significant breaches in data confidentiality and integrity, leading to unauthorized data manipulation.
Affected Version(s)
ceph Red Hat Ceph Storage 4
ceph Red Hat Openshift Container Storage 4.2
