Ceph
Vendor:
First CVE: Oct 3, 2016 · Active for 9 years
7
Total CVEs
Bottom 1%
1.4
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ceph over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 3, 2016
9 years ago
Most Recent CVE
Feb 7, 2020
2,359 days ago
CVE Severity & Scoring
Ceph7 CVEs
57%
43%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (28.6%)
Network4 (57.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (42.9%)
High1 (14.3%)
None3 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10222HIGH A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HT | Nov 8, 2019 | 7.5 | 27 | NO | NO |
CVE-2018-10861HIGH A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images | Jul 10, 2018 | 8.1 | 25 | NO | NO |
CVE-2018-1129MEDIUM A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message p | Jul 10, 2018 | 6.5 | 22 | NO | NO |
CVE-2017-12155MEDIUM A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access | Dec 12, 2017 | 6.3 | 22 | NO | NO |
CVE-2016-7031HIGH The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL. | Oct 3, 2016 | 7.5 | 19 | NO | NO |
CVE-2020-1700MEDIUM A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts result | Feb 7, 2020 | 6.5 | 18 | NO | NO |
CVE-2017-7519MEDIUM In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library. | Jul 27, 2018 | 4.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Ceph
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 13.2.1 | 2 | 7.3 | 2.6% | 0 | 0 |
| 13.2.0 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.7 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.6 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.5 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.4 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.3 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.2 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.1 | 2 | 7.3 | 2.6% | 0 | 0 |
| 12.2.0 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.9 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.8 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.7 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.6 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.5 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.4 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.3 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.2 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.11 | 2 | 7.3 | 2.6% | 0 | 0 |
| 10.2.10 | 2 | 7.3 | 2.6% | 0 | 0 |