Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Ceph — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in Ceph, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common weakness types for the Ceph product, a distributed storage system developed by Red Hat and the open-source community. It collects vulnerability records spanning from the initial public releases of Ceph through the most recent patches and advisories provided by the vendor. Here, users can track a vendor's security advisories, understand a specific weakness class within the context of distributed object and block storage, and look up a product's comprehensive vulnerability history. The data includes various severities and attack vectors relevant to Ceph’s architecture, such as remote code execution, privilege escalation, and information disclosure flaws found in components like RADOS gateway, OSD, or MDS. By centralizing these findings, the page serves as a reference for security professionals assessing the risk profile of Ceph deployments. It highlights how weaknesses have evolved over time and identifies patterns in how the maintainer addresses reported issues. This resource supports due diligence for enterprises relying on Ceph for scalable storage solutions, enabling them to evaluate past incidents and current mitigation strategies without sifting through disparate sources. The information is derived from official vendor notifications, public CVE databases, and third-party security research, ensuring a broad coverage of known issues. Readers can use this aggregation to compare Ceph’s security posture against industry standards or to inform internal patch management schedules.

Vendor: Red Hat

CVE IDTitleCVSSSeverityPublished
CVE-2024-47866 RGW DoS attack with empty HTTP header in S3 object copy CWE-20 7.5 High2025-11-12
CVE-2024-48916 Ceph is vulnerable to authentication bypass through RadosGW CWE-345 8.1 High2025-07-30
CVE-2025-52555 CephFS Permission Escalation Vulnerability in Ceph Fuse mounted FS CWE-269 6.5 Medium2025-06-26
CVE-2022-3854 Red Hat Ceph 安全漏洞 CWE-177 6.5 -2023-03-06
CVE-2022-3650 Red Hat Ceph 安全漏洞 CWE-842 7.8 -2023-01-17
CVE-2021-3979 Red Hat Ceph Storage 授权问题漏洞 CWE-327 4.0 -2022-08-25
CVE-2022-0670 Red Hat Ceph 安全漏洞 CWE-863 8.1 -2022-07-25
CVE-2021-3531 Red Hat Ceph 输入验证错误漏洞 CWE-20 5.3 -2021-05-18
CVE-2021-3524 Red Hat Ceph Storage 注入漏洞 CWE-20 6.5 -2021-05-17
CVE-2021-20288 红帽 Red Hat Ceph 授权问题漏洞 CWE-287 9.8 -2021-04-15
CVE-2020-25678 部分Red Hat产品 安全漏洞 CWE-312 5.5 -2021-01-08
CVE-2020-27781 OpenStack 安全漏洞 CWE-522 7.8 -2020-12-18
CVE-2020-25660 Red Hat Ceph 安全漏洞 CWE-294 7.5 -2020-11-23
CVE-2020-10736 Red Hat Ceph 安全漏洞 CWE-285 8.0 High2020-06-22
CVE-2020-1760 Red Hat Ceph Object Gateway 跨站脚本漏洞 CWE-79 5.8 Medium2020-04-23
CVE-2020-1699 Red Hat Ceph Storage Ceph仪表板路径遍历漏洞 CWE-200 7.5 High2020-04-21
CVE-2020-1759 多款Red Hat产品安全特征问题漏洞 CWE-323 6.4 Medium2020-04-13
CVE-2020-1700 Ceph RGW Beast 资源管理错误漏洞 CWE-400 6.5 Medium2020-02-07
CVE-2019-10222 Red Hat Ceph 资源管理错误漏洞 CWE-755 7.5 -2019-11-08
CVE-2019-3821 Red Hat ceph 资源管理错误漏洞 CWE-772 7.5 -2019-03-27
CVE-2018-16889 debug 日志信息泄露漏洞 CWE-532 7.5 -2019-01-28
CVE-2018-14662 Red Hat Ceph 信息泄露漏洞 CWE-285 5.7 -2019-01-15
CVE-2018-16846 Red Hat Ceph 输入验证错误漏洞 CWE-770 6.5 -2019-01-15
CVE-2016-9579 Ceph 输入验证错误漏洞 CWE-20 7.5 -2018-08-01
CVE-2016-8626 Red Hat Ceph 输入验证漏洞 CWE-476 6.5 -2018-07-31
CVE-2017-7519 Red Hat Ceph 格式化字符串漏洞 CWE-134 4.4 -2018-07-27
CVE-2018-1129 Red Hat Ceph 安全漏洞 CWE-284 6.5 -2018-07-10
CVE-2018-1128 Red Hat Ceph 授权问题漏洞 CWE-294 6.8 -2018-07-10
CVE-2018-10861 Red Hat Ceph 安全漏洞 CWE-285 8.1 -2018-07-10

All 29 known CVE vulnerabilities affecting Ceph with full Chinese analysis, references, and POCs where available.