Vulnerabilidades em ceph
7 resultadosAnálise Vexday
Ceph apresenta um perfil de risco controlado com apenas 3 vulnerabilidades registradas e nenhuma sob exploração ativa. A fraqueza dominante é validação inadequada de entrada (CWE-20), sem ocorrências críticas ou publicações recentes, indicando um cenário de vulnerabilidades de baixa severidade já conhecidas e estabilizadas.
CVE-2024-47866HIGHRGW DoS attack with empty HTTP header in S3 object copyEPSS 0.4%CVE-2025-52555MEDIUMCephFS Permission Escalation Vulnerability in Ceph Fuse mounted FSEPSS 0.2%CVE-2024-48916HIGHCeph is vulnerable to authentication bypass through RadosGWEPSS 0.2%CVE-2026-54330HIGHCeph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalationEPSS 0.2%CVE-2026-39944HIGHCeph: CephX AES Authentication errorEPSS 0.2%CVE-2026-50152CRITICALCeph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only usersEPSS 0.2%CVE-2025-30156HIGHCeph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgeryEPSS 0.1%