CVE-2018-1129: Ceph

Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

Affected products

  • Ceph Ceph: version 10.2.0 only; version 10.2.1 only; version 10.2.2 only; version 10.2.3 only; version 10.2.4 only; version 10.2.5 only; …
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Opensuse Leap: version 15.0 only
  • Red Hat Ceph Storage: version 1.3 only; version 3 only
  • Red Hat Ceph Storage Mon: version 2 only; version 3 only
  • Red Hat Ceph Storage Osd: version 2 only; version 3 only
  • Red Hat Enterprise Linux: version 7.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-07-10. Last modified 2026-06-17.