BIT-ceph-2021-20288

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ceph/BIT-ceph-2021-20288.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-ceph-2021-20288
Aliases
Published
2026-03-20T09:05:43.098Z
Modified
2026-03-20T10:00:42.605177Z
Summary
[none]
Details

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHXGETAUTHSESSIONKEY requests, it doesn't sanitize otherkeys, allowing key reuse. An attacker who can request a globalid can exploit the ability of any user to request a global_id previously associated with another user, as ceph does not force the reuse of old keys to generate new ones. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Database specific
{
    "cpes": [
        "cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / ceph

Package

Name
ceph
Purl
pkg:bitnami/ceph

Severity

  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.2.21

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ceph/BIT-ceph-2021-20288.json"