Ceph

Vendor:

First CVE: Oct 3, 2016 · Active for 9 years

7
Total CVEs
Bottom 1%
1.4
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ceph over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2016
9 years ago
Most Recent CVE
Feb 7, 2020
2,359 days ago

CVE Severity & Scoring

Ceph7 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local2 (28.6%)
Network4 (57.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (42.9%)
High1 (14.3%)
None3 (42.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HT
Nov 8, 20197.527NONO
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images
Jul 10, 20188.125NONO
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message p
Jul 10, 20186.522NONO
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access
Dec 12, 20176.322NONO
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Oct 3, 20167.519NONO
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts result
Feb 7, 20206.518NONO
In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
Jul 27, 20184.418NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Ceph

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
13.2.127.32.6%00
13.2.027.32.6%00
12.2.727.32.6%00
12.2.627.32.6%00
12.2.527.32.6%00
12.2.427.32.6%00
12.2.327.32.6%00
12.2.227.32.6%00
12.2.127.32.6%00
12.2.027.32.6%00
10.2.927.32.6%00
10.2.827.32.6%00
10.2.727.32.6%00
10.2.627.32.6%00
10.2.527.32.6%00
10.2.427.32.6%00
10.2.327.32.6%00
10.2.227.32.6%00
10.2.1127.32.6%00
10.2.1027.32.6%00