UNKNOWN OpenStack
CVE-2020-27781
OSSN-0087: = Ceph user credential leakage to consumers of OpenStack Manila =
OpenStack Manila users can request access on a share to any
arbitrary cephx user, including privileged pre-existing users
of a Ceph cluster. They can then retrieve access secret keys
for these pre-existing ceph users via Manila APIs. A cephx
client user name and access secret key are required to mount
a Native CephFS manila share. With a secret key, a manila user
can impersonate a pre-existing ceph user and gain capabilities
to manipulate resources that the manila user was never intended
to have
Affected Products
- OpenStack Shared File Systems Service (Manila) versions Mitaka (2.0.0) through Victoria (11.0.0)
- Ceph Luminous (<=v12.2.13), Mimic (<=v13.2.10), Nautilus (<=v14.2.15), Octopus (<=v15.2.7)
- CVE-2020-27781
References
This unknown severity vulnerability was published on 2026-08-27 via OpenStack. Affected: OpenStack Shared File Systems Service (Manila) versions Mitaka (2.0.0) through Victoria (11.0.0), Ceph Luminous (<=v12.2.13), Mimic (<=v13.2.10), Nautilus (<=v14.2.15), Octopus (<=v15.2.7), CVE-2020-27781.
vulnfeed aggregates 11337 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.