Security Advisory

CVE-2020-10736

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-06-22 17:49:38
Last updated 2024-08-04 11:14:14
Assigner redhat
State PUBLISHED

Description

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.