UBUNTU-CVE-2021-20288

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2021-20288
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-20288.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-20288
Related
Published
2021-04-15T15:15:00Z
Modified
2021-04-15T15:15:00Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHXGETAUTHSESSIONKEY requests, it doesn't sanitize otherkeys, allowing key reuse. An attacker who can request a globalid can exploit the ability of any user to request a global_id previously associated with another user, as ceph does not force the reuse of old keys to generate new ones. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

References

Affected packages

Ubuntu:Pro:14.04:LTS / ceph

Package

Name
ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.67.4-0ubuntu2
0.67.4-0ubuntu3
0.72-0ubuntu1
0.72.1-0ubuntu1
0.72.1-2
0.72.1-3
0.72.2-1
0.72.2-2
0.78-0ubuntu1
0.79-0ubuntu1
0.80.1-0ubuntu1
0.80.1-0ubuntu1.1
0.80.5-0ubuntu0.14.04.1
0.80.7-0ubuntu0.14.04.1
0.80.9-0ubuntu0.14.04.1
0.80.9-0ubuntu0.14.04.2
0.80.10-0ubuntu0.14.04.1
0.80.10-0ubuntu1.14.04.2
0.80.10-0ubuntu1.14.04.3
0.80.11-0ubuntu1.14.04.1
0.80.11-0ubuntu1.14.04.2
0.80.11-0ubuntu1.14.04.3
0.80.11-0ubuntu1.14.04.4
0.80.11-0ubuntu1.14.04.4+esm2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:16.04:LTS / ceph

Package

Name
ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.94.3-0ubuntu2
0.94.5-0ubuntu1

9.*

9.2.0-0ubuntu3
9.2.0-0ubuntu4
9.2.0-0ubuntu5
9.2.0-0ubuntu6

10.*

10.0.2-0ubuntu1
10.0.3-0ubuntu1
10.0.5-0ubuntu1
10.1.0-0ubuntu1
10.1.1-0ubuntu1
10.1.2-0ubuntu1
10.2.0-0ubuntu0.16.04.1
10.2.0-0ubuntu0.16.04.2
10.2.2-0ubuntu0.16.04.2
10.2.3-0ubuntu0.16.04.2
10.2.5-0ubuntu0.16.04.1
10.2.6-0ubuntu0.16.04.1
10.2.7-0ubuntu0.16.04.1
10.2.9-0ubuntu0.16.04.1
10.2.10-0ubuntu0.16.04.1
10.2.11-0ubuntu0.16.04.1
10.2.11-0ubuntu0.16.04.2
10.2.11-0ubuntu0.16.04.3
10.2.11-0ubuntu0.16.04.3+esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / ceph

Package

Name
ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

12.*

12.2.0-0ubuntu1
12.2.1-0ubuntu1
12.2.2-0ubuntu1
12.2.2-0ubuntu2
12.2.4-0ubuntu1
12.2.4-0ubuntu1.1
12.2.7-0ubuntu0.18.04.1
12.2.8-0ubuntu0.18.04.1
12.2.8-0ubuntu0.18.04.2
12.2.11-0ubuntu0.18.04.1
12.2.11-0ubuntu0.18.04.2
12.2.12-0ubuntu0.18.04.1
12.2.12-0ubuntu0.18.04.2
12.2.12-0ubuntu0.18.04.3
12.2.12-0ubuntu0.18.04.4
12.2.12-0ubuntu0.18.04.5
12.2.13-0ubuntu0.18.04.2
12.2.13-0ubuntu0.18.04.3
12.2.13-0ubuntu0.18.04.4
12.2.13-0ubuntu0.18.04.5
12.2.13-0ubuntu0.18.04.6
12.2.13-0ubuntu0.18.04.7
12.2.13-0ubuntu0.18.04.8
12.2.13-0ubuntu0.18.04.10
12.2.13-0ubuntu0.18.04.11
12.2.13-0ubuntu0.18.04.11+esm1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / ceph

Package

Name
ceph
Purl
pkg:deb/ubuntu/ceph@15.2.12-0ubuntu0.20.04.1?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.2.12-0ubuntu0.20.04.1

Affected versions

14.*

14.2.2-0ubuntu3
14.2.2-0ubuntu4
14.2.4-0ubuntu1
14.2.4-0ubuntu2
14.2.4-0ubuntu3

15.*

15.1.0-0ubuntu2
15.1.0-0ubuntu3
15.1.1-0ubuntu1
15.2.0-0ubuntu1
15.2.0-0ubuntu2
15.2.1-0ubuntu1
15.2.1-0ubuntu2
15.2.3-0ubuntu0.20.04.1
15.2.3-0ubuntu0.20.04.2
15.2.5-0ubuntu0.20.04.1
15.2.7-0ubuntu0.20.04.1
15.2.7-0ubuntu0.20.04.2
15.2.8-0ubuntu0.20.04.1
15.2.11-0ubuntu0.20.04.2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "python3-rgw-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "python3-ceph-argparse": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mds": "15.2.12-0ubuntu0.20.04.1",
            "rbd-fuse-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "rbd-mirror-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "libradospp-dev": "15.2.12-0ubuntu0.20.04.1",
            "libradosstriper1-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "rbd-nbd": "15.2.12-0ubuntu0.20.04.1",
            "python3-rgw": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mds-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "rados-objclass-dev": "15.2.12-0ubuntu0.20.04.1",
            "ceph-immutable-object-cache": "15.2.12-0ubuntu0.20.04.1",
            "ceph-fuse-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "rbd-nbd-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "ceph-resource-agents": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-modules-core": "15.2.12-0ubuntu0.20.04.1",
            "librbd1-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "python3-cephfs-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "ceph-common": "15.2.12-0ubuntu0.20.04.1",
            "python3-rbd-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "libcephfs2": "15.2.12-0ubuntu0.20.04.1",
            "ceph-immutable-object-cache-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-diskprediction-local": "15.2.12-0ubuntu0.20.04.1",
            "rbd-fuse": "15.2.12-0ubuntu0.20.04.1",
            "libcephfs-java": "15.2.12-0ubuntu0.20.04.1",
            "ceph-common-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "radosgw": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-dashboard": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-k8sevents": "15.2.12-0ubuntu0.20.04.1",
            "libcephfs-jni": "15.2.12-0ubuntu0.20.04.1",
            "radosgw-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "python3-cephfs": "15.2.12-0ubuntu0.20.04.1",
            "ceph-osd": "15.2.12-0ubuntu0.20.04.1",
            "librados-dev": "15.2.12-0ubuntu0.20.04.1",
            "libradosstriper-dev": "15.2.12-0ubuntu0.20.04.1",
            "ceph-fuse": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "librgw2": "15.2.12-0ubuntu0.20.04.1",
            "python3-ceph": "15.2.12-0ubuntu0.20.04.1",
            "librados2": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-cephadm": "15.2.12-0ubuntu0.20.04.1",
            "librados-dev-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "ceph": "15.2.12-0ubuntu0.20.04.1",
            "librados2-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mon": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mon-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "libcephfs2-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "librbd-dev": "15.2.12-0ubuntu0.20.04.1",
            "cephadm": "15.2.12-0ubuntu0.20.04.1",
            "python3-ceph-common": "15.2.12-0ubuntu0.20.04.1",
            "rbd-mirror": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-diskprediction-cloud": "15.2.12-0ubuntu0.20.04.1",
            "ceph-base-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "libcephfs-dev": "15.2.12-0ubuntu0.20.04.1",
            "ceph-osd-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "librbd1": "15.2.12-0ubuntu0.20.04.1",
            "python3-rados": "15.2.12-0ubuntu0.20.04.1",
            "python3-rbd": "15.2.12-0ubuntu0.20.04.1",
            "python3-rados-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "cephfs-shell": "15.2.12-0ubuntu0.20.04.1",
            "libcephfs-jni-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "librgw2-dbgsym": "15.2.12-0ubuntu0.20.04.1",
            "ceph-base": "15.2.12-0ubuntu0.20.04.1",
            "librgw-dev": "15.2.12-0ubuntu0.20.04.1",
            "ceph-mgr-rook": "15.2.12-0ubuntu0.20.04.1",
            "libradosstriper1": "15.2.12-0ubuntu0.20.04.1"
        }
    ]
}