Information disclosure in Ceph - CVE-2018-14662
Published: January 21, 2019
Vulnerability identifier: #VU17098
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14662
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.
The vulnerability exists due to information exposure. A remote attacker read only permissions can steal dm-crypt encryption keys used in ceph disk encryption.
Affected software
Ceph
Red Hat Ceph Storage
Ubuntu
Opensuse
Fedora
ceph (Ubuntu package)
ceph
Red Hat Ceph Storage
Ubuntu
Opensuse
Fedora
ceph (Ubuntu package)
ceph
How to mitigate CVE-2018-14662
Update to version 13.2.4.
Ceph - update to 13.2.4
ceph (Ubuntu package) - addressed in versions 0.80.11-0ubuntu1.14.04.4+esm3, 10.2.11-0ubuntu0.16.04.3+esm2
ceph - update to 12.2.11-1.fc29
ceph (Ubuntu package) - addressed in versions 0.80.11-0ubuntu1.14.04.4+esm3, 10.2.11-0ubuntu0.16.04.3+esm2
ceph - update to 12.2.11-1.fc29