MGASA-2023-0139
Dashboard / Vulnerabilities / MGASA-2023-0139
Summary: Updated ceph packages fix security vulnerability
Details: Openstack manilla owning a Ceph File system "share", enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. (CVE-2022-0670) Privilege escalation and privileged information disclosure (CVE-2022-3650)
References: https://advisories.mageia.org/MGASA-2023-0139.html, https://bugs.mageia.org/show_bug.cgi?id=30677, https://docs.ceph.com/en/latest/security/CVE-2022-0670/, https://github.com/ceph/ceph/pull/48713/commits
Affected packages
Package
Name: ceph
Purl: pkg:rpm/mageia/ceph?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
