Ceph
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 8, 2015 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →libceph: validate OSD extent maps before cursor advance
ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode
ceph: cap delegated inode count in ceph_parse_deleg_inos()
ceph: do not repeat ceph_trim_dentries() if no progress possible
Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation
Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery
[OSSN-0108] Multiple authentication vulnerabilities in Ceph affecting OpenStack
Ceph 20.2.4 and Ceph 19.2.6 aleased with 4 security fixes.
CVE-2024-47866 Ceph: RGW DoS via improper input validation.
Monitor Ceph in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.