First published: Tue May 08 2018(Updated: )
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ceph | <2:10.2.10-28.el7c | 2:10.2.10-28.el7c |
redhat/ceph-ansible | <0:3.0.39-1.el7c | 0:3.0.39-1.el7c |
redhat/ceph | <2:12.2.4-30.el7c | 2:12.2.4-30.el7c |
redhat/cephmetrics | <0:1.0.1-1.el7c | 0:1.0.1-1.el7c |
redhat/nfs-ganesha | <0:2.5.5-6.el7c | 0:2.5.5-6.el7c |
debian/ceph | 12.2.11+dfsg1-2.1 12.2.11+dfsg1-2.1+deb10u1 14.2.21-1 16.2.11+ds-2 16.2.11+ds-5 | |
debian/linux | 4.19.249-2 4.19.289-2 5.10.197-1 5.10.191-1 6.1.55-1 6.1.52-1 6.5.6-1 6.5.8-1 | |
redhat/ceph | <10.2.11 | 10.2.11 |
redhat/ceph | <12.2.6 | 12.2.6 |
redhat/ceph | <13.2.1 | 13.2.1 |
Redhat Ceph Storage | =3 | |
Redhat Ceph Storage Mon | =2 | |
Redhat Ceph Storage Mon | =3 | |
Redhat Ceph Storage Osd | =2 | |
Redhat Ceph Storage Osd | =3 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Redhat Ceph | >=10.2.0<=13.2.1 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2018-1128 is a vulnerability in the cephx authentication protocol that allows attackers to authenticate with the ceph service and perform unauthorized actions.
CVE-2018-1128 has a severity rating of 7.5 (high).
Versions 10.2.11, 12.2.6, and 13.2.1 of the ceph package are affected by CVE-2018-1128.
The recommended fix for CVE-2018-1128 is to update to version 10.2.11, 12.2.6, or 13.2.1 of the ceph package, depending on your current version.
You can find more information about CVE-2018-1128 at the following references: [1] http://tracker.ceph.com/issues/24836 [2] https://github.com/ceph/ceph/commit/5ead97120e07054d80623dada90a5cc764c28468 [3] https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1599406