CVE-2018-1128

1 karet z 1 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2018-1128

EPSS 0.01

Pro tohle CVE zatím žádné hodnocení CVSS nemáme. Buď ho záznam CVE Programu neuvádí, nebo ještě nebyl vydaný — advisories často citují rezervované ID dřív, než záznam vznikne.

1

CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

Information published.

EPSS 0.01 CVE-2018-1128 Ceph US

Microsoft Security ·