Candidate: CVE-2018-10861 PublicDate: 2018-07-10 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10861 Description: A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected. Ubuntu-Description: Notes: Bugs: http://tracker.ceph.com/issues/24838 https://bugzilla.redhat.com/show_bug.cgi?id=1593308 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H [8.1 HIGH] Patches_ceph: upstream: https://github.com/ceph/ceph/commit/975528f632f73fbffa3f1fee304e3bbe3296cffc upstream: https://github.com/ceph/ceph/commit/4e1bc0cd6a0aaa76eb1936d1717a4ab07e179da6 (mimic) upstream: https://github.com/ceph/ceph/commit/c41a2e696e26a7f747afeeeb44f96c322bd739af (jewel) upstream_ceph: released (10.2.11,12.2.6) precise/esm_ceph: ignored (end of ESM support, was needs-triage) trusty_ceph: ignored (reached end-of-life) trusty/esm_ceph: needs-triage xenial_ceph: not-affected (10.2.11-0ubuntu0.16.04.1) esm-infra/xenial_ceph: not-affected (10.2.11-0ubuntu0.16.04.1) artful_ceph: ignored (reached end-of-life) bionic_ceph: not-affected (12.2.7-0ubuntu0.18.04.1) cosmic_ceph: not-affected (13.2.4+dfsg1-0ubuntu0.18.10.1) disco_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) eoan_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) focal_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) groovy_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) hirsute_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) impish_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) jammy_ceph: not-affected (13.2.4+dfsg1-0ubuntu1) devel_ceph: not-affected (13.2.4+dfsg1-0ubuntu1)