Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MicroCeph path traversal issue in the remote-import API
Vulnerability Description
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
Vulnerability Type
相对路径遍历
Vulnerability Title
Canonical MicroCeph 路径遍历漏洞
Vulnerability Description
Canonical MicroCeph是英国Canonical公司开源的一个轻量级分布式存储集群管理平台。 Canonical MicroCeph存在路径遍历漏洞,该漏洞源于remote-import API中的路径遍历问题,可能导致持有可信集群mTLS证书或加入令牌的攻击者操纵/var/snap/microceph中的文件,造成守护进程中断和集群状态污染。
CVSS Information
N/A
Vulnerability Type
N/A