RHSA-2019:2541: Moderate: Red Hat Ceph Storage 3.3 security, bug fix, and enhancement update
Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines the most stable version of the Ceph storage system with a Ceph management platform, deployment utilities, and support services.Security Fix(es): ceph: ListBucket max-keys has no defined limit in the RGW codebase (CVE-2018-16846) ceph: debug logging for v4 auth does not sanitize encryption keys (CVE-2018-16889) ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key (CVE-2018-14662) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es) and Enhancement(s):For detailed information on changes in this release, see the Red Hat Ceph Storage 3.3 Release Notes available at:https://access.redhat.com/documentation/en-us/redhatcephstorage/3.3/html/releasenotes/index
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2541?
The severity of RHSA-2019:2541 is classified as moderate.
How do I fix RHSA-2019:2541?
You can fix RHSA-2019:2541 by updating Red Hat Ceph Storage to the latest patched version.
What vulnerabilities are addressed in RHSA-2019:2541?
RHSA-2019:2541 addresses issues related to inadequate handling of ListBucket max-keys.
Which versions of Red Hat Ceph Storage are affected by RHSA-2019:2541?
RHSA-2019:2541 affects specific versions of Red Hat Ceph Storage, but the exact versions should be checked in the advisory.
Is there a workaround for RHSA-2019:2541?
No specific workaround for RHSA-2019:2541 is documented; applying the update is recommended.