Skip to main content

Vendor/product archive

redhat / ceph CVEs

Beta · best-effort

17 CVEs tagged to redhat / ceph0 Critical, 6 High, 11 Medium, 0 Low, 0 Unrated.

CVE-2024-47866

Published Nov 12, 2025

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3650

Published Jan 17, 2023

A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged informati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27839

Published May 26, 2021

A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16889

Published Jan 28, 2019

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1128

Published Jul 10, 2018

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who i…

CVSS 7.5 · High

CVE-2018-7262

Published Mar 19, 2018

In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16818

Published Dec 20, 2017

RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not neces…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5245

Published Dec 3, 2015

CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP respon…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1