Vulnerability Details CVE-2020-27781
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.3%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 3.6
Products affected by CVE-2020-27781
-
cpe:2.3:a:redhat:ceph:0.1
-
cpe:2.3:a:redhat:ceph:0.10
-
cpe:2.3:a:redhat:ceph:0.11
-
cpe:2.3:a:redhat:ceph:0.12
-
cpe:2.3:a:redhat:ceph:0.13
-
cpe:2.3:a:redhat:ceph:0.14
-
cpe:2.3:a:redhat:ceph:0.15
-
cpe:2.3:a:redhat:ceph:0.16
-
cpe:2.3:a:redhat:ceph:0.16.1
-
cpe:2.3:a:redhat:ceph:0.17
-
cpe:2.3:a:redhat:ceph:0.18
-
cpe:2.3:a:redhat:ceph:0.19
-
cpe:2.3:a:redhat:ceph:0.19.1
-
cpe:2.3:a:redhat:ceph:0.2
-
cpe:2.3:a:redhat:ceph:0.20
-
cpe:2.3:a:redhat:ceph:0.20.1
-
cpe:2.3:a:redhat:ceph:0.20.2
-
cpe:2.3:a:redhat:ceph:0.21
-
cpe:2.3:a:redhat:ceph:0.21.1
-
cpe:2.3:a:redhat:ceph:0.21.2
-
cpe:2.3:a:redhat:ceph:0.21.3
-
cpe:2.3:a:redhat:ceph:0.22
-
cpe:2.3:a:redhat:ceph:0.22.1
-
cpe:2.3:a:redhat:ceph:0.22.2
-
cpe:2.3:a:redhat:ceph:0.23
-
cpe:2.3:a:redhat:ceph:0.23.1
-
cpe:2.3:a:redhat:ceph:0.23.2
-
cpe:2.3:a:redhat:ceph:0.24
-
cpe:2.3:a:redhat:ceph:0.24.1
-
cpe:2.3:a:redhat:ceph:0.24.2
-
cpe:2.3:a:redhat:ceph:0.24.3
-
cpe:2.3:a:redhat:ceph:0.25
-
cpe:2.3:a:redhat:ceph:0.25.1
-
cpe:2.3:a:redhat:ceph:0.25.2
-
cpe:2.3:a:redhat:ceph:0.26
-
cpe:2.3:a:redhat:ceph:0.27
-
cpe:2.3:a:redhat:ceph:0.27.1
-
cpe:2.3:a:redhat:ceph:0.28
-
cpe:2.3:a:redhat:ceph:0.28.1
-
cpe:2.3:a:redhat:ceph:0.28.2
-
cpe:2.3:a:redhat:ceph:0.29
-
cpe:2.3:a:redhat:ceph:0.29.1
-
cpe:2.3:a:redhat:ceph:0.3
-
cpe:2.3:a:redhat:ceph:0.30
-
cpe:2.3:a:redhat:ceph:0.31
-
cpe:2.3:a:redhat:ceph:0.32
-
cpe:2.3:a:redhat:ceph:0.33
-
cpe:2.3:a:redhat:ceph:0.34
-
cpe:2.3:a:redhat:ceph:0.35
-
cpe:2.3:a:redhat:ceph:0.36
-
cpe:2.3:a:redhat:ceph:0.37
-
cpe:2.3:a:redhat:ceph:0.38
-
cpe:2.3:a:redhat:ceph:0.39
-
cpe:2.3:a:redhat:ceph:0.4
-
cpe:2.3:a:redhat:ceph:0.40
-
cpe:2.3:a:redhat:ceph:0.41
-
cpe:2.3:a:redhat:ceph:0.42
-
cpe:2.3:a:redhat:ceph:0.42.1
-
cpe:2.3:a:redhat:ceph:0.42.2
-
cpe:2.3:a:redhat:ceph:0.43
-
cpe:2.3:a:redhat:ceph:0.44
-
cpe:2.3:a:redhat:ceph:0.44.1
-
cpe:2.3:a:redhat:ceph:0.44.2
-
cpe:2.3:a:redhat:ceph:0.45
-
cpe:2.3:a:redhat:ceph:0.46
-
cpe:2.3:a:redhat:ceph:0.47
-
cpe:2.3:a:redhat:ceph:0.47.1
-
cpe:2.3:a:redhat:ceph:0.47.2
-
cpe:2.3:a:redhat:ceph:0.47.3
-
cpe:2.3:a:redhat:ceph:0.48
-
cpe:2.3:a:redhat:ceph:0.48.1
-
cpe:2.3:a:redhat:ceph:0.48.2
-
cpe:2.3:a:redhat:ceph:0.48.3
-
cpe:2.3:a:redhat:ceph:0.49
-
cpe:2.3:a:redhat:ceph:0.5
-
cpe:2.3:a:redhat:ceph:0.50
-
cpe:2.3:a:redhat:ceph:0.51
-
cpe:2.3:a:redhat:ceph:0.52
-
cpe:2.3:a:redhat:ceph:0.53
-
cpe:2.3:a:redhat:ceph:0.54
-
cpe:2.3:a:redhat:ceph:0.55
-
cpe:2.3:a:redhat:ceph:0.55.1
-
cpe:2.3:a:redhat:ceph:0.56
-
cpe:2.3:a:redhat:ceph:0.56.1
-
cpe:2.3:a:redhat:ceph:0.56.2
-
cpe:2.3:a:redhat:ceph:0.56.3
-
cpe:2.3:a:redhat:ceph:0.56.4
-
cpe:2.3:a:redhat:ceph:0.56.5
-
cpe:2.3:a:redhat:ceph:0.56.6
-
cpe:2.3:a:redhat:ceph:0.56.7
-
cpe:2.3:a:redhat:ceph:0.57
-
cpe:2.3:a:redhat:ceph:0.58
-
cpe:2.3:a:redhat:ceph:0.59
-
cpe:2.3:a:redhat:ceph:0.6
-
cpe:2.3:a:redhat:ceph:0.60
-
cpe:2.3:a:redhat:ceph:0.61
-
cpe:2.3:a:redhat:ceph:0.61.1
-
cpe:2.3:a:redhat:ceph:0.61.2
-
cpe:2.3:a:redhat:ceph:0.61.3
-
cpe:2.3:a:redhat:ceph:0.61.4
-
cpe:2.3:a:redhat:ceph:0.61.5
-
cpe:2.3:a:redhat:ceph:0.61.6
-
cpe:2.3:a:redhat:ceph:0.61.7
-
cpe:2.3:a:redhat:ceph:0.61.8
-
cpe:2.3:a:redhat:ceph:0.61.9
-
cpe:2.3:a:redhat:ceph:0.62
-
cpe:2.3:a:redhat:ceph:0.63
-
cpe:2.3:a:redhat:ceph:0.64
-
cpe:2.3:a:redhat:ceph:0.65
-
cpe:2.3:a:redhat:ceph:0.66
-
cpe:2.3:a:redhat:ceph:0.67
-
cpe:2.3:a:redhat:ceph:0.67.1
-
cpe:2.3:a:redhat:ceph:0.67.10
-
cpe:2.3:a:redhat:ceph:0.67.11
-
cpe:2.3:a:redhat:ceph:0.67.2
-
cpe:2.3:a:redhat:ceph:0.67.3
-
cpe:2.3:a:redhat:ceph:0.67.4
-
cpe:2.3:a:redhat:ceph:0.67.5
-
cpe:2.3:a:redhat:ceph:0.67.6
-
cpe:2.3:a:redhat:ceph:0.67.7
-
cpe:2.3:a:redhat:ceph:0.67.8
-
cpe:2.3:a:redhat:ceph:0.67.9
-
cpe:2.3:a:redhat:ceph:0.68
-
cpe:2.3:a:redhat:ceph:0.69
-
cpe:2.3:a:redhat:ceph:0.7
-
cpe:2.3:a:redhat:ceph:0.7.1
-
cpe:2.3:a:redhat:ceph:0.7.2
-
cpe:2.3:a:redhat:ceph:0.7.3
-
cpe:2.3:a:redhat:ceph:0.70
-
cpe:2.3:a:redhat:ceph:0.71
-
cpe:2.3:a:redhat:ceph:0.72
-
cpe:2.3:a:redhat:ceph:0.72.1
-
cpe:2.3:a:redhat:ceph:0.72.2
-
cpe:2.3:a:redhat:ceph:0.73
-
cpe:2.3:a:redhat:ceph:0.74
-
cpe:2.3:a:redhat:ceph:0.75
-
cpe:2.3:a:redhat:ceph:0.76
-
cpe:2.3:a:redhat:ceph:0.77
-
cpe:2.3:a:redhat:ceph:0.78
-
cpe:2.3:a:redhat:ceph:0.79
-
cpe:2.3:a:redhat:ceph:0.8
-
cpe:2.3:a:redhat:ceph:0.80
-
cpe:2.3:a:redhat:ceph:0.80.1
-
cpe:2.3:a:redhat:ceph:0.80.10
-
cpe:2.3:a:redhat:ceph:0.80.11
-
cpe:2.3:a:redhat:ceph:0.80.2
-
cpe:2.3:a:redhat:ceph:0.80.3
-
cpe:2.3:a:redhat:ceph:0.80.4
-
cpe:2.3:a:redhat:ceph:0.80.5
-
cpe:2.3:a:redhat:ceph:0.80.6
-
cpe:2.3:a:redhat:ceph:0.80.7
-
cpe:2.3:a:redhat:ceph:0.80.8
-
cpe:2.3:a:redhat:ceph:0.80.8.1
-
cpe:2.3:a:redhat:ceph:0.80.8.2
-
cpe:2.3:a:redhat:ceph:0.80.8.4
-
cpe:2.3:a:redhat:ceph:0.80.8.5
-
cpe:2.3:a:redhat:ceph:0.80.9
-
cpe:2.3:a:redhat:ceph:0.81
-
cpe:2.3:a:redhat:ceph:0.82
-
cpe:2.3:a:redhat:ceph:0.83
-
cpe:2.3:a:redhat:ceph:0.84
-
cpe:2.3:a:redhat:ceph:0.85
-
cpe:2.3:a:redhat:ceph:0.86
-
cpe:2.3:a:redhat:ceph:0.87
-
cpe:2.3:a:redhat:ceph:0.87.1
-
cpe:2.3:a:redhat:ceph:0.87.2
-
cpe:2.3:a:redhat:ceph:0.88
-
cpe:2.3:a:redhat:ceph:0.89
-
cpe:2.3:a:redhat:ceph:0.9
-
cpe:2.3:a:redhat:ceph:0.90
-
cpe:2.3:a:redhat:ceph:0.91
-
cpe:2.3:a:redhat:ceph:0.92
-
cpe:2.3:a:redhat:ceph:0.93
-
cpe:2.3:a:redhat:ceph:0.94
-
cpe:2.3:a:redhat:ceph:0.94.1
-
cpe:2.3:a:redhat:ceph:0.94.1.1
-
cpe:2.3:a:redhat:ceph:0.94.1.2
-
cpe:2.3:a:redhat:ceph:0.94.1.3
-
cpe:2.3:a:redhat:ceph:0.94.1.4
-
cpe:2.3:a:redhat:ceph:0.94.1.5
-
cpe:2.3:a:redhat:ceph:0.94.1.6
-
cpe:2.3:a:redhat:ceph:0.94.1.7
-
cpe:2.3:a:redhat:ceph:0.94.10
-
cpe:2.3:a:redhat:ceph:0.94.2
-
cpe:2.3:a:redhat:ceph:0.94.3
-
cpe:2.3:a:redhat:ceph:0.94.3.1
-
cpe:2.3:a:redhat:ceph:0.94.3.2
-
cpe:2.3:a:redhat:ceph:0.94.3.3
-
cpe:2.3:a:redhat:ceph:0.94.4
-
cpe:2.3:a:redhat:ceph:0.94.5
-
cpe:2.3:a:redhat:ceph:0.94.6
-
cpe:2.3:a:redhat:ceph:0.94.7
-
cpe:2.3:a:redhat:ceph:0.94.8
-
cpe:2.3:a:redhat:ceph:0.94.9
-
cpe:2.3:a:redhat:ceph:10.0.0
-
cpe:2.3:a:redhat:ceph:10.0.1
-
cpe:2.3:a:redhat:ceph:10.0.2
-
cpe:2.3:a:redhat:ceph:10.0.3
-
cpe:2.3:a:redhat:ceph:10.0.4
-
cpe:2.3:a:redhat:ceph:10.0.5
-
cpe:2.3:a:redhat:ceph:10.1.0
-
cpe:2.3:a:redhat:ceph:10.1.1
-
cpe:2.3:a:redhat:ceph:10.1.2
-
cpe:2.3:a:redhat:ceph:10.2.0
-
cpe:2.3:a:redhat:ceph:10.2.01
-
cpe:2.3:a:redhat:ceph:10.2.1
-
cpe:2.3:a:redhat:ceph:10.2.10
-
cpe:2.3:a:redhat:ceph:10.2.11
-
cpe:2.3:a:redhat:ceph:10.2.2
-
cpe:2.3:a:redhat:ceph:10.2.3
-
cpe:2.3:a:redhat:ceph:10.2.4
-
cpe:2.3:a:redhat:ceph:10.2.5
-
cpe:2.3:a:redhat:ceph:10.2.6
-
cpe:2.3:a:redhat:ceph:10.2.7
-
cpe:2.3:a:redhat:ceph:10.2.8
-
cpe:2.3:a:redhat:ceph:10.2.9
-
cpe:2.3:a:redhat:ceph:11.0.0
-
cpe:2.3:a:redhat:ceph:11.0.1
-
cpe:2.3:a:redhat:ceph:11.0.2
-
cpe:2.3:a:redhat:ceph:11.1.0
-
cpe:2.3:a:redhat:ceph:11.1.1
-
cpe:2.3:a:redhat:ceph:11.2.0
-
cpe:2.3:a:redhat:ceph:11.2.1
-
cpe:2.3:a:redhat:ceph:12.0.0
-
cpe:2.3:a:redhat:ceph:12.0.1
-
cpe:2.3:a:redhat:ceph:12.0.2
-
cpe:2.3:a:redhat:ceph:12.0.3
-
cpe:2.3:a:redhat:ceph:12.1.0
-
cpe:2.3:a:redhat:ceph:12.1.1
-
cpe:2.3:a:redhat:ceph:12.1.2
-
cpe:2.3:a:redhat:ceph:12.1.3
-
cpe:2.3:a:redhat:ceph:12.1.4
-
cpe:2.3:a:redhat:ceph:12.2.0
-
cpe:2.3:a:redhat:ceph:12.2.1
-
cpe:2.3:a:redhat:ceph:12.2.10
-
cpe:2.3:a:redhat:ceph:12.2.2
-
cpe:2.3:a:redhat:ceph:12.2.3
-
cpe:2.3:a:redhat:ceph:12.2.4
-
cpe:2.3:a:redhat:ceph:12.2.5
-
cpe:2.3:a:redhat:ceph:12.2.6
-
cpe:2.3:a:redhat:ceph:12.2.7
-
cpe:2.3:a:redhat:ceph:12.2.8
-
cpe:2.3:a:redhat:ceph:12.2.9
-
cpe:2.3:a:redhat:ceph:13.0.0
-
cpe:2.3:a:redhat:ceph:13.0.1
-
cpe:2.3:a:redhat:ceph:13.0.2
-
cpe:2.3:a:redhat:ceph:13.1.0
-
cpe:2.3:a:redhat:ceph:13.1.1
-
cpe:2.3:a:redhat:ceph:13.2.0
-
cpe:2.3:a:redhat:ceph:13.2.1
-
cpe:2.3:a:redhat:ceph:13.2.2
-
cpe:2.3:a:redhat:ceph:13.2.3
-
cpe:2.3:a:redhat:ceph:13.2.4
-
cpe:2.3:a:redhat:ceph:14.0.0
-
cpe:2.3:a:redhat:ceph:14.0.1
-
cpe:2.3:a:redhat:ceph:14.2.14
-
cpe:2.3:a:redhat:ceph:14.2.15
-
cpe:2.3:a:redhat:ceph:15.0.0
-
cpe:2.3:a:redhat:ceph:15.1.0
-
cpe:2.3:a:redhat:ceph:15.1.1
-
cpe:2.3:a:redhat:ceph:15.2.0
-
cpe:2.3:a:redhat:ceph:15.2.1
-
cpe:2.3:a:redhat:ceph:15.2.2
-
cpe:2.3:a:redhat:ceph:15.2.3
-
cpe:2.3:a:redhat:ceph:15.2.4
-
cpe:2.3:a:redhat:ceph:15.2.5
-
cpe:2.3:a:redhat:ceph:15.2.6
-
cpe:2.3:a:redhat:ceph:15.2.7
-
cpe:2.3:a:redhat:ceph:16.0.0
-
cpe:2.3:a:redhat:ceph:16.1.0
-
cpe:2.3:a:redhat:ceph:9.0.0
-
cpe:2.3:a:redhat:ceph:9.0.1
-
cpe:2.3:a:redhat:ceph:9.0.2
-
cpe:2.3:a:redhat:ceph:9.0.3
-
cpe:2.3:a:redhat:ceph:9.1.0
-
cpe:2.3:a:redhat:ceph:9.2.0
-
cpe:2.3:a:redhat:ceph:9.2.1
-
cpe:2.3:a:redhat:ceph_storage:2.0
-
cpe:2.3:a:redhat:ceph_storage:3.0
-
cpe:2.3:a:redhat:ceph_storage:4.0
-
cpe:2.3:a:redhat:openshift_container_platform:4.0
-
cpe:2.3:a:redhat:openstack_platform:13.0
-
cpe:2.3:o:fedoraproject:fedora:33