Bug 13694

Summary: [CVE 21] ceph 15.2.7 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: RESOLVED DUPLICATE QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: e.kosachev, s.matveev, v.potapov, y.tumanov
Version: All   
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2020-25678, CVE-2020-27781, CVE-2020-27839, CVE-2022-0670,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-10-18 19:59:49 MSK
Please patch CVEs for package ceph version 15.2.7
  
INFO (CVEs are): ceph 15.2.7
 cves found
CVE-2020-25678
Desc: A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-25678
Severity: MEDIUM
CVE-2020-27781
Desc: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-27781
Severity: HIGH
CVE-2020-27839
Desc: A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-27839
Severity: MEDIUM
CVE-2022-0670
Desc: A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-0670
Severity: CRITICAL
Comment 1 Vladimir Potapov 2023-10-20 11:40:14 MSK

*** This bug has been marked as a duplicate of bug 13826 ***