CVE-2020-27781
Last modified
CVE-2020-27781 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Ceph | < 14.2.16 |
| Redhat | Ceph | >= 15.0.0, < 15.2.8 |
| Redhat | Ceph | >= 16.0.0, < 16.2.0 |
| Redhat | Ceph Storage | 2.0 |
| Redhat | Ceph Storage | 3.0 |
| Redhat | Ceph Storage | 4.0 |
| Redhat | Openshift Container Platform | 4.0 |
| Redhat | Openstack Platform | 13.0 |
| Fedoraproject | Fedora | 33 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1900109Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/202105-39Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1900109Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/202105-39Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27781?
How severe is CVE-2020-27781?
How do I fix CVE-2020-27781?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27776A flaw was found in ImageMagick in MagickCore/statistic.c. A…3.3
- CVE-2020-27777A flaw was found in the way RTAS handled memory accesses in …6.7
- CVE-2020-27778A flaw was found in Poppler in the way certain PDF files wer…7.5
- CVE-2020-27779A flaw was found in grub2 in versions prior to 2.06. The cut…7.5
- CVE-2020-2778Vulnerability in the Java SE product of Oracle Java SE (comp…3.7
- CVE-2020-27780A flaw was found in Linux-Pam in versions prior to 1.5.1 in …9.8
- CVE-2020-27782A flaw was found in the Undertow AJP connector. Malicious re…7.5
- CVE-2020-27783A XSS vulnerability was discovered in python-lxml's clean mo…6.1
- CVE-2020-27784A vulnerability was found in the Linux kernel, where accessi…5.5
- CVE-2020-27785Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-27786A flaw was found in the Linux kernel’s implementation of MID…7.8
- CVE-2020-27787A Segmentaation fault was found in UPX in invert_pt_dynamic(…5.5
Are you affected by CVE-2020-27781?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
