Ceph 是一个开源的分布式存储平台,提供对象存储、块存储和文件存储。在 20.2.4 和 19.2.6 之前的版本中,Monitor 订阅处理器未能对配置密钥(config-key)存储库的访问进行适当的授权,使得仅具备 权限的任意 CephX 用户通过发送一条特制的 消息即可读取整个配置密钥存储库。该存储库中保存着敏感信息,包括 OSD LUKS 磁盘加密口令;在由 cephadm 管理的集群中,还包含 cephadm 用于访问集群中所有主机的 SSH 私钥。由于在默认 cephadm 配置下,该 SSH 私钥
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-30156 | 8.9 HIGH | Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential for |
| CVE-2026-39944 | 8.8 HIGH | Ceph: CephX AES Authentication error |
| CVE-2026-54330 | 8.1 HIGH | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing pr |
No comments yet