Vulnerability Name:

CVE-2020-27781 (CCN-193255)

Assigned:2020-12-16
Published:2020-12-16
Updated:2021-06-03
Summary:User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.
CVSS v3 Severity:7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): None
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
5.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-522
CWE-522
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-27781

Source: MISC
Type: Issue Tracking, Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1900109

Source: XF
Type: UNKNOWN
openstack-cve202027781-info-disc(193255)

Source: CCN
Type: Ceph GIT Repository
Ceph

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2020-fcafbe7225

Source: CCN
Type: Opendev Web site
Shared filesystem management project for OpenStack.

Source: CCN
Type: oss-sec Mailing List, Wed, 16 Dec 2020 16:08:01 -0500
CVE-2020-27781 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila

Source: GENTOO
Type: Third Party Advisory
GLSA-202105-39

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:ceph:*:*:*:*:*:*:*:* (Version < 14.2.16)
  • OR cpe:/a:redhat:ceph:*:*:*:*:*:*:*:* (Version >= 15.0.0 and < 15.2.8)
  • OR cpe:/a:redhat:ceph:*:*:*:*:*:*:*:* (Version >= 16.0.0 and < 16.2.0)

  • Configuration 2:
  • cpe:/a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7460
    P
    ceph-common-16.2.11.58+g38d6afd3b78-150400.3.6.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:95316
    P
    Security update for fwupd (Moderate)
    2022-08-05
    oval:org.opensuse.security:def:3236
    P
    libpolkit0-0.113-5.18.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3362
    P
    sblim-sfcb-1.4.8-17.3.4 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94516
    P
    ceph-common-16.2.7.654+gd5a90ff46f0-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:95165
    P
    xen-4.16.0_08-150400.2.12 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2886
    P
    ceph-common-16.2.7.654+gd5a90ff46f0-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:24
    P
    ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:102029
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2022-03-29
    oval:org.opensuse.security:def:953
    P
    Security update for ldns (Moderate)
    2022-03-02
    oval:org.opensuse.security:def:94474
    P
    (Moderate)
    2022-02-04
    oval:org.opensuse.security:def:112053
    P
    ceph-16.2.6.463+g22e7612f9ad-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:101878
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:96768
    P
    rsync-3.1.3-2.10 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:101187
    P
    libdjvulibre-devel-3.5.27-9.28 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62042
    P
    ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100800
    P
    ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71783
    P
    ceph-common-15.2.9.83+g4275378de0-3.17.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:5768
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:100009
    P
    (Important)
    2021-02-09
    oval:org.opensuse.security:def:110674
    P
    Security update for ceph (Moderate)
    2021-01-16
    oval:org.opensuse.security:def:75925
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:66490
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:91197
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:97157
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:97439
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:75558
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:104129
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:64325
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:108695
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:98162
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:66857
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:5401
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:104852
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:73447
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:90474
    P
    Security update for ceph (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:110927
    P
    Security update for ceph (Important)
    2020-12-25
    oval:org.opensuse.security:def:5617
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:107853
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:103013
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:73573
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:108544
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:66706
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:117368
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:75774
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:64451
    P
    Security update for ceph (Important)
    2020-12-21
    BACK
    redhat ceph *
    redhat ceph *
    redhat ceph *
    redhat ceph storage 2.0
    redhat ceph storage 3.0
    redhat ceph storage 4.0
    redhat openshift container platform 4.0
    redhat openstack platform 13.0
    fedoraproject fedora 33