CVE-2021-20288 log

Source
Severity High
Remote Yes
Type Insufficient validation
Description
An authentication flaw was found in ceph. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another user, as ceph does not force the reuse of old keys to generate new ones.
Group Package Affected Fixed Severity Status Ticket
AVG-1826 ceph 15.2.10-1 High Vulnerable FS#70451
References
https://www.openwall.com/lists/oss-security/2021/04/14/2
https://github.com/ceph/ceph/commit/1f57617d5edb45a8a696eac7c910e8fc44c934a3
https://github.com/ceph/ceph/commit/9f3efe7cd1a780b91e5c8cfee192a0c51d0151dc