]> git.proxmox.com Git - ceph.git/blame - ceph/doc/security/CVE-2022-0670.rst
import ceph quincy 17.2.6
[ceph.git] / ceph / doc / security / CVE-2022-0670.rst
CommitLineData
39ae355f
TL
1.. _CVE-2022-0670:
2
3CVE-2022-0670: Native-CephFS Manila Path-restriction bypass
4===========================================================
5
6Summary
7-------
8
9Users who were running OpenStack Manila to export native CephFS and who
10upgraded their Ceph cluster from Nautilus (or earlier) to a later
11major version were vulnerable to an attack by malicious users. The
12vulnerability allowed users to obtain access to arbitrary portions of
13the CephFS filesystem hierarchy instead of being properly restricted
14to their own subvolumes. The vulnerability is due to a bug in the
15"volumes" plugin in Ceph Manager. This plugin is responsible for
16managing Ceph File System subvolumes, which are used by OpenStack
17Manila services as a way to provide shares to Manila users.
18
19Again, this vulnerability impacts only OpenStack Manila clusters that
20provided native CephFS access to their users.
21
22Affected versions
23-----------------
24
25Any version of Ceph running OpenStack Manila that was upgraded from Nautilus
26or earlier.
27
28Fixed versions
29--------------
30
31* Quincy v17.2.2 (and later)
32* Pacific v16.2.10 (and later)
33* Octopus v15.2.17
34
35Recommendations
36---------------
37
38#. Users should upgrade to a patched version of Ceph at their earliest
39 convenience.
40
41#. Administrators who are
42 concerned they may have been impacted should audit the CephX keys in
43 their cluster for proper path restrictions.