Authentication Flaw in Ceph Affects Various Versions
CVE-2021-20288
7.2HIGH
Summary
An authentication flaw exists in Ceph that affects versions prior to 14.2.20. This vulnerability allows an attacker capable of requesting a global_id to exploit the system by reusing authentication keys associated with other users. Due to the lack of proper sanitization of keys during the CEPHX_GET_AUTH_SESSION_KEY requests, this flaw raises concerns regarding data confidentiality, integrity, and system availability, posing significant risks to users and the environment where Ceph operates.
Affected Version(s)
ceph ceph 14.2.20
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved