Vulnerabilidades en The Ceph Project
4 resultadosAnálisis Vexday
O Ceph Project apresenta footprint de risco reduzido com apenas 4 CVEs conhecidas e nenhuma em exploração ativa. A fraqueza dominante é exposição de informações (CWE-200), sem vulnerabilidades críticas ou recentes que demandem ação imediata. O perfil sugere risco baixo sob perspectiva de inteligência de ameaças.
CVE-2019-10222HIGHA flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crashEPSS 4.6%CVE-2020-1699HIGHA path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has beeEPSS 2.1%CVE-2020-1759MEDIUMA vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discoEPSS 1.6%CVE-2018-16889MEDIUMCeph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in lEPSS 0.5%