Ceph 是一个开源分布式存储平台,提供对象存储、块存储和文件存储功能。在低于 20.2.4 和 19.2.6 的版本中,CephX 认证协议使用 AES-128-CBC 加密票据(tickets),但采用的是未认证的加密模式:使用硬编码的初始化向量(IV),且没有消息认证机制。这使得攻击者可以伪造凭证(credentials),从而获得整个集群的访问权限。 由于密文具有可篡改性(malleable),且监控节点(Monitor)会加密攻击者指定的实体名称,因此,一个持有低权限密钥并能观察 CephX 流量的攻击者
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50152 | 9.1 CRITICAL | Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing c |
| CVE-2026-39944 | 8.8 HIGH | Ceph: CephX AES Authentication error |
| CVE-2026-54330 | 8.1 HIGH | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing pr |
No comments yet