Security restrictions bypass in Ceph - CVE-2018-1128

 

Security restrictions bypass in Ceph - CVE-2018-1128

Published: August 28, 2018


Vulnerability identifier: #VU14542
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1128
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an adjacent attacker to conduct replay attack on the target system.

The vulnerability exists in ceph branches master, mimic, luminous and jewel due to cephx authentication protocol did not verify ceph clients correctly. An adjacent attacker with access to ceph cluster network who is able to sniff packets on network can authenticate with ceph service, perform actions allowed by ceph service, conduct replay attack and bypass security restrictions.


Affected software

Ceph
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Opensuse
Ubuntu
Fedora
Red Hat Ceph Storage
cephmetrics (Red Hat package)
nfs-ganesha (Red Hat package)
ceph-ansible (Red Hat package)
ceph
ceph-base (Ubuntu package)
ceph-common (Ubuntu package)
ceph (Ubuntu package)

How to mitigate CVE-2018-1128

Install update from vendor's website.

Ceph - addressed in versions 10.2.10-28.el7cp, 12.2.4-30.el7cp
Red Hat Ceph Storage - addressed in versions 2.5, 3
cephmetrics (Red Hat package) - update to 1.0.1-1.el7cp
nfs-ganesha (Red Hat package) - update to 2.5.5-6.el7cp
ceph-ansible (Red Hat package) - update to 3.0.39-1.el7cp
ceph - addressed in versions 12.2.6-1.fc27, 12.2.6-1.fc28, 12.2.7-1.fc27
ceph-base (Ubuntu package) - addressed in versions 15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3
ceph-common (Ubuntu package) - addressed in versions 15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3
ceph (Ubuntu package) - addressed in versions 15.2.7-0ubuntu0.20.04.2, 15.2.7-0ubuntu0.20.10.3

External References

Related Security Bulletins