MEDIUM 6.5 Microsoft
CVE-2018-1129
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable.
Microsoft Security Update 2018-Jul: A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable.
Affected Products
- azl3 ceph 18.2.1-1 on Azure Linux 3.0
- azl3 ceph 16.2.10-3 on Azure Linux 3.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-1129
- https://nvd.nist.gov/vuln/detail/CVE-2018-1129
This medium severity vulnerability with a CVSS score of 6.5 was published on 2018-07-10 via Microsoft. Affected: azl3 ceph 18.2.1-1 on Azure Linux 3.0, azl3 ceph 16.2.10-3 on Azure Linux 3.0.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.