Known vulnerabilities in ceph (Ubuntu package)

Software CPE: cpe:2.3:o:canonical:ceph_ubuntu_package:*:*:*:*:*:ubuntu:*:*
Total vulnerabilities: 15
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ceph (Ubuntu package) ceph (Ubuntu package) is affected by 15 known vulnerabilities: 1 high, 9 medium, 5 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118528 - Improper input validation
CVE-2024-47866
CWE-20 Medium
No
No
0.80.11-0ubuntu1.14.04.4+esm4, 10.2.11-0ubuntu0.16.04.3+esm3, 12.2.13-0ubuntu0.18.04.11+esm2, 15.2.17-0ubuntu0.20.04.6+esm1, 17.2.9-0ubuntu0.22.04.2, 19.2.3-0ubuntu0.24.04.3, 19.2.3-0ubuntu1.25.10.3 14.11.2025 SB2025111411
SB2025121914
SB2026020608
and 3 more
#VU114318 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2021-3524
CWE-113 Low
No
No
0.80.11-0ubuntu1.14.04.4+esm3, 10.2.11-0ubuntu0.16.04.3+esm2 21.08.2025 SB2021051735
SB2025082110
SB2021051423
and 7 more
#VU102357 - Improper Authentication
CVE-2024-48916
CWE-287 High
No
No
17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1 06.01.2025 SB2025010643
SB2025010644
SB2025010702
and 11 more
#VU82112 - Improper Authorization
CVE-2023-43040
CWE-285 Medium
Available
No
Ubuntu Pro, 15.2.17-0ubuntu0.20.04.6, 17.2.6-0ubuntu0.22.04.3, 18.2.0-0ubuntu3.1 17.10.2023 SB2023101761
SB2023112450
SB2024012922
and 5 more
#VU74055 - Improper input validation
CVE-2022-3854
CWE-20 Medium
No
No
12.2.13-0ubuntu0.18.04.11, 15.2.17-0ubuntu0.20.04.3, 17.2.5-0ubuntu0.22.04.3, 17.2.5-0ubuntu0.22.10.3 27.03.2023 SB2023022857
SB2023032745
SB2023032746
and 3 more
#VU72630 - Incorrect Default Permissions
CVE-2022-3650
CWE-276 Low
No
No
12.2.13-0ubuntu0.18.04.11, 15.2.17-0ubuntu0.20.04.3, 17.2.5-0ubuntu0.22.04.3, 17.2.5-0ubuntu0.22.10.3, 17.2.6-0ubuntu0.23.04.2 28.02.2023 SB2023022857
SB2023022873
SB2023030907
and 10 more
#VU66551 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2021-3979
CWE-327 Low
No
No
12.2.13-0ubuntu0.18.04.11, 15.2.17-0ubuntu0.20.04.3, 17.2.5-0ubuntu0.22.04.3, 17.2.5-0ubuntu0.22.10.3 16.08.2022 SB2022081730
SB2022081731
SB2022122122
and 6 more
#VU66440 - Permissions, Privileges, and Access Controls
CVE-2022-0670
CWE-264 Medium
No
No
12.2.13-0ubuntu0.18.04.11, 15.2.17-0ubuntu0.20.04.3, 17.2.5-0ubuntu0.22.04.3, 17.2.5-0ubuntu0.22.10.3 12.08.2022 SB2022081213
SB2022081215
SB2022081223
and 10 more
#VU48684 - Authentication Bypass Using an Alternate Path or Channel
CVE-2020-25660
CWE-288 Medium
No
No
15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3 23.11.2020 SB2020112701
SB2020112704
SB2020120405
and 6 more
#VU48628 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2020-10753
CWE-74 Medium
No
No
15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3 26.06.2020 SB2020062624
SB2020112420
SB2020112704
and 7 more
#VU28173 - Improper Authorization
CVE-2020-10736
CWE-285 Medium
No
No
15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3 21.05.2020 SB2020052138
SB2020112419
SB2021012849
#VU26150 - Resource Management Errors
CVE-2020-1700
CWE-399 Medium
No
No
12.2.12-0ubuntu0.18.04.5, 14.2.4-0ubuntu0.19.10.2 18.03.2020 SB2020020721
SB2020031804
SB2020020806
and 1 more
#VU20465 - Resource Management Errors
CVE-2019-10222
CWE-399 Medium
No
No
12.2.12-0ubuntu0.18.04.1, 13.2.6-0ubuntu0.19.04.1, 13.2.6-0ubuntu0.19.04.2 29.08.2019 SB2019082901
SB2019082902
SB2019082904
and 6 more
#VU17098 - Exposure of sensitive information to an unauthorized actor
CVE-2018-14662
CWE-200 Low
No
No
0.80.11-0ubuntu1.14.04.4+esm3, 10.2.11-0ubuntu0.16.04.3+esm2 21.01.2019 SB2019012103
SB2019030809
SB2019042801
and 4 more
#VU14542 - Permissions, Privileges, and Access Controls
CVE-2018-1128
CWE-264 Low
No
No
15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3 28.08.2018 SB2018082808
SB2018111511
SB2019042801
and 9 more