CVE Database
/

CVE-2018-1129

Back to search

CVE-2018-1129

Published: Jul 10, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

VendorProductVersions

Red Hat, Inc.

ceph

affected
all versions in branches master, mimic, luminous and jewel

Weaknesses (CWE)

References

RHSA-2018:2261
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2177
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2179
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2274
vendor-advisory
x_refsource_REDHAT
DSA-4339
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2019:1284
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now