PT-2026-82767 · Ceph · Ceph
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Ceph versions prior to 20.2.4
Ceph versions prior to 19.2.6
Description
The Monitor subscription handler fails to properly authorize access to the configuration-key store. A CephX user with
mon allow r capabilities can read the entire store by sending a crafted MMonSubscribe message. The configuration-key store contains sensitive secrets, such as OSD LUKS disk-encryption passphrases and the SSH private key used by cephadm to access hosts in the cluster. Under default cephadm configurations, this key provides root access to every node, allowing a low-privileged read-only account to achieve full cluster and host compromise.Recommendations
Update to version 20.2.4 or later.
Update to version 19.2.6 or later.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ceph