CVE-2018-1129 describes a medium-severity vulnerability in the cephx authentication protocol affecting Ceph branches master, mimic, luminous, and jewel, as well as products from Debian, openSUSE, and Red Hat. An attacker with access to the Ceph cluster network could bypass signature checks by altering message payloads, leading to high integrity impact without confidentiality or availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:1.3:*:*:*:*:*:*:* | ||
3CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage:3:*:*:*:*:*:*:* | ||
2CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage_mon:2:*:*:*:*:*:*:* | ||
3CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage_mon:3:*:*:*:*:*:*:* | ||
2CPE matchmatch criteria | cpe:2.3:a:redhat:ceph_storage_osd:2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2018-1129
Jun 11, 2024A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable.
Jul 10, 2018ceph: cephx uses weak signatures
Jul 9, 2018