CVE-2018-10861: Ceph
High severity, CVSS 8.1. EPSS: 3.2% chance of exploitation in the next 30 days.
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.
Affected products
- Ceph Ceph: version 10.2.0 only; version 10.2.1 only; version 10.2.2 only; version 10.2.3 only; version 10.2.4 only; version 10.2.5 only; …
- Debian Debian Linux: version 9.0 only
- Opensuse Leap: version 15.0 only
- Red Hat Ceph Storage: version 3 only
- Red Hat Ceph Storage Mon: version 2 only; version 3 only
- Red Hat Ceph Storage Osd: version 2 only; version 3 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-07-10. Last modified 2026-06-17.