ceph ceph CVE-2022-0670 vulnerability in Ceph and Other Products
Published on July 25, 2022

product logo product logo product logo product logo product logo
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

Vendor Advisory Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2022-0670 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2022-0670

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-0670 are published in these products:

 
 
 
 
 
 

Exploit Probability

EPSS
0.20%
Percentile
41.39%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.