Rapid7

vulnerability

CentOS Linux: CVE-2018-14662: Moderate: Red Hat Ceph Storage 3.3 security, bug fix, and enhancement update (CESA-2019:2538)

Severity
3
CVSS
(AV:A/AC:L/Au:S/C:P/I:N/A:N)
Published
Jan 15, 2019
Added
Mar 5, 2020
Modified
May 25, 2023

Description

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.

Solutions

centos-upgrade-ceph-ansiblecentos-upgrade-ceph-basecentos-upgrade-ceph-commoncentos-upgrade-ceph-debuginfocentos-upgrade-ceph-fusecentos-upgrade-ceph-iscsi-configcentos-upgrade-ceph-mdscentos-upgrade-ceph-radosgwcentos-upgrade-ceph-selinuxcentos-upgrade-cephmetrics-ansiblecentos-upgrade-libcephfs-develcentos-upgrade-libcephfs2centos-upgrade-libntirpccentos-upgrade-libntirpc-debuginfocentos-upgrade-librados-develcentos-upgrade-libradosstriper1centos-upgrade-librbd-develcentos-upgrade-librgw-develcentos-upgrade-librgw2centos-upgrade-nfs-ganeshacentos-upgrade-nfs-ganesha-cephcentos-upgrade-nfs-ganesha-debuginfocentos-upgrade-nfs-ganesha-rgwcentos-upgrade-python-cephfscentos-upgrade-python-crypto-debuginfocentos-upgrade-python-rgwcentos-upgrade-python2-cryptocentos-upgrade-rbd-mirror
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.