UBUNTU-CVE-2022-0670
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-0670
UBUNTU-CVE-2022-0670
Summary:
Details: A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
References: https://ubuntu.com/security/CVE-2022-0670, https://ceph.io/en/news/blog/2022/v17-2-2-quincy-released/, https://lists.fedoraproject.org/archives/list/[email protected]/message/5O3XMDFZWA2FWU6GAYOVSFJPOUTXN42N/, https://docs.ceph.com/en/latest/security/CVE-2022-0670/, https://ubuntu.com/security/notices/USN-6063-1, https://www.cve.org/CVERecord?id=CVE-2022-0670
Affected packages
Package
Name: ceph
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
