Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-27781

23
FAUCET Score

CVE-2020-27781 describes a privilege escalation vulnerability in OpenStack Manila when using Native CephFS. An attacker can manipulate and steal user credentials, including those of "admin" users, by requesting share access to an arbitrary cephx user. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0, impacting various Fedora and Red Hat Ceph/OpenStack products. The vulnerability has a CVSS score of 7.1 (HIGH), indicating a local attack vector with low complexity, requiring low privileges and no user interaction, leading to high confidentiality and integrity impacts. The EPSS score is very low, suggesting a low probability of exploitation in the wild. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 14.2.16CPE matchmatch criteria
cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:*
>= 15.0.0, < 15.2.8CPE matchmatch criteria
cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:*
>= 16.0.0, < 16.2.0CPE matchmatch criteria
cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 60th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/rook-ceph-rhel8-operator:4.6-82.8c7ed584.release_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 3 - ELSFixed in: ceph-2:12.2.12-139.el7cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 3 - ELSFixed in: ceph-ansible-0:3.2.56-1.el7cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 3 - ELSFixed in: cephmetrics-0:2.0.10-1.el7cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 3 - ELSFixed in: grafana-0:5.2.4-3.el7cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 3 - ELSFixed in: tcmu-runner-0:1.4.0-3.el7cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 4.2Fixed in: ceph-2:14.2.11-95.el8cp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/cephcsi-rhel8:4.6-54.49cf5efdd.release_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/mcg-core-rhel8:5.6.0-42.6a01c5fc0.5.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/mcg-rhel8-operator:5.6.0-41.2279a46.5.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/ocs-must-gather-rhel8:4.6-78.3b7455e4.release_4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/ocs-operator-bundle:4.6.2-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Storage 4.6.0 on RHEL-8Fixed in: ocs4/ocs-rhel8-operator:4.6-78.3b7455e4.release_4.6
View patch
redhatvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Openshift Container Storage 4Fixed in: ceph
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: ceph

Vendor Advisories (1)

redhatCVE-2020-27781Important

ceph: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila

Dec 16, 2020

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory
lists.debian.org / debian-lts-announce/2023/10/msg00034.html
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZJ7FFROL25FYRL6FMI33VRKOD74LINRP
security.gentoo.org / glsa/202105-39
Third Party Advisory