CVE-2018-1128

MEDIUM

Description

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

References

http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.html

http://tracker.ceph.com/issues/24836

https://access.redhat.com/errata/RHSA-2018:2177

https://access.redhat.com/errata/RHSA-2018:2179

https://access.redhat.com/errata/RHSA-2018:2261

https://access.redhat.com/errata/RHSA-2018:2274

https://bugzilla.redhat.com/show_bug.cgi?id=1575866

https://github.com/ceph/ceph/commit/5ead97120e07054d80623dada90a5cc764c28468

https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html

https://www.debian.org/security/2018/dsa-4339

Details

Source: MITRE

Published: 2018-07-10

Updated: 2019-05-21

Type: CWE-287

Risk Information

CVSS v2.0

Base Score: 5.4

Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 5.5

Severity: MEDIUM

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.6

Severity: HIGH