CVE-2018-10861

Source
https://cve.org/CVERecord?id=CVE-2018-10861
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-10861.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-10861
Downstream
Related
Published
2018-07-10T14:29:00.213Z
Modified
2026-05-17T11:55:20.647416001Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:a:redhat:ceph_storage:3:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "3"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "redhat:ceph_storage"
        },
        {
            "cpes": [
                "cpe:2.3:a:redhat:ceph_storage_mon:3:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "3"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "redhat:ceph_storage_mon"
        },
        {
            "cpes": [
                "cpe:2.3:a:redhat:ceph_storage_osd:3:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "3"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "redhat:ceph_storage_osd"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "7.0"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "redhat:enterprise_linux_desktop"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "7.0"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "redhat:enterprise_linux_server"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "last_affected": "7.0"
                }
            ],
            "source": "CPE_FIELD",
            "vendor_product": "redhat:enterprise_linux_workstation"
        }
    ]
}
References

Affected packages