VYPR
Unrated severityOSV Advisory· Published Jan 15, 2019· Updated Aug 5, 2024

CVE-2018-14662

CVE-2018-14662

Description

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.

Affected products

13

Patches

1
b10be4d44915

13.2.4

https://github.com/ceph/cephJenkins Build Slave UserJan 4, 2019via osv
2 files changed · +7 1
  • CMakeLists.txt+1 1 modified
    @@ -1,7 +1,7 @@
     cmake_minimum_required(VERSION 2.8.12)
     
     project(ceph CXX C ASM)
    -set(VERSION 13.2.3)
    +set(VERSION 13.2.4)
     
     if(POLICY CMP0028)
       cmake_policy(SET CMP0028 NEW)
    
  • debian/changelog+6 0 modified
    @@ -1,3 +1,9 @@
    +ceph (13.2.4-1) stable; urgency=medium
    +
    +  * New upstream release
    +
    + -- Ceph Release Team <ceph-maintainers@ceph.com>  Fri, 04 Jan 2019 15:40:41 +0000
    +
     ceph (13.2.3-1) stable; urgency=medium
     
       * New upstream release
    

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

8

News mentions

0

No linked articles in our index yet.