PT-2022-7554 · Openstack+7 · Openstack Manila+8

Kotresh Hr

·

Published

2022-07-21

·

Updated

2026-03-20

·

CVE-2022-0670

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Openstack manilla versions prior to RHCS 5.2 and Ceph 17.2.2
Description A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system.
Recommendations For Openstack manilla versions prior to RHCS 5.2, update to RHCS 5.2 or later to resolve the issue. For Ceph versions prior to 17.2.2, update to Ceph 17.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "volumes" plugin in Ceph Manager to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2304
ALT-PU-2022-2350
ALT-PU-2023-1853
ALT-PU-2023-4361
AZL-10387
AZL-38305
BDU:2024-07308
BIT-CEPH-2022-0670
CVE-2022-0670
MGASA-2023-0139
OESA-2022-2125
OPENSUSE-SU-2024:12662-1
RHSA-2022:5997
SUSE-SU-2023:1580-1
SUSE-SU-2023:1581-1
SUSE-SU-2023:1581-2
SUSE-SU-2023:1584-1
SUSE-SU-2023_1580-1
SUSE-SU-2023_1581-1
USN-6063-1

Affected Products

Alt Linux
Astra Linux
Ceph
Debian
Linuxmint
Openstack Manila
Rhcs
Suse
Ubuntu