ZeroHour

CVE-2018-10861

CVSS 3.0
8.1 high
EPSS
3%p87
Published
()
Modified
Description

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

Vendors
cephredhatopensusedebian
Products
ceph, ceph storage, ceph storage mon, ceph storage osd, enterprise linux desktop, enterprise linux server, enterprise linux workstation, leap, debian linux
Weakness
CWE-285, CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

In the news

No ingested article mentions this CVE yet.