356
VMScore

CVE-2018-16846

Published: 15/01/2019 Updated: 19/04/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

It was found in Ceph versions prior to 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat ceph

debian debian linux 8.0

debian debian linux 9.0

opensuse leap 15.0

redhat ceph storage 2.0

redhat ceph storage 3.0

redhat enterprise linux server 7.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.10

canonical ubuntu linux 19.04

Vendor Advisories

Several security issues were fixed in Ceph ...
Synopsis Moderate: Red Hat Ceph Storage 33 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 33 on Ubuntu 1604Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulne ...
Synopsis Moderate: Red Hat Ceph Storage 33 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Ceph Storage 33 on Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate ...
Debian Bug report logs - #921947 CVE-2018-16846 Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 10 Feb 2019 13:15:02 UTC Severity: important Tags: security, upstream Found in version ceph/12210+dfsg1-1 Fix ...
Debian Bug report logs - #921948 CVE-2018-14662 Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 10 Feb 2019 13:18:02 UTC Severity: important Tags: security, upstream Found in version ceph/12210+dfsg1-1 Fix ...
Debian Bug report logs - #918969 ceph: CVE-2018-16889: debug logging for v4 auth does not sanitize encryption keys Package: src:ceph; Maintainer for src:ceph is Ceph Maintainers <ceph-maintainers@listscephcom>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 11 Jan 2019 08:06:02 UTC Severity: impor ...
A flaw was found in the way the ListBucket function max-keys has no defined limit in the RGW codebase An authenticated ceph RGW user can cause a denial of service attack against OMAPs holding bucked indices ...