CVE-2020-1759 - log back

CVE-2020-1759 edited at 23 Nov 2020 23:31:36
References
+ https://docs.ceph.com/en/latest/releases/octopus/#v15-2-1-octopus
https://docs.ceph.com/en/latest/releases/nautilus/#v14-2-9-nautilus
https://www.openwall.com/lists/oss-security/2020/04/07/2
https://github.com/ceph/ceph/pull/34482
https://github.com/ceph/ceph/commit/47c7e623546a7a33bd6bbddfb899fa9c9a40f40a
https://github.com/ceph/ceph/commit/f6c5ad8a5f534d73cba9c6bd794a89e879c46ecc
CVE-2020-1759 edited at 22 Nov 2020 18:37:46
Remote
- Unknown
+ Remote
Description
- A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
+ A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2, where a nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
CVE-2020-1759 edited at 22 Nov 2020 18:28:01
Severity
- Unknown
+ Medium
Type
- Unknown
+ Private key recovery
Description
+ A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
References
+ https://docs.ceph.com/en/latest/releases/nautilus/#v14-2-9-nautilus
+ https://www.openwall.com/lists/oss-security/2020/04/07/2
+ https://github.com/ceph/ceph/pull/34482
+ https://github.com/ceph/ceph/commit/47c7e623546a7a33bd6bbddfb899fa9c9a40f40a
+ https://github.com/ceph/ceph/commit/f6c5ad8a5f534d73cba9c6bd794a89e879c46ecc
CVE-2020-1759 created at 22 Nov 2020 18:17:21
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes