BIT-ceph-2020-1759

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ceph/BIT-ceph-2020-1759.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ceph-2020-1759
Aliases
Published
2026-03-20T09:05:38.136Z
Modified
2026-03-20T10:00:10.271594Z
Summary
[none]
Details

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / ceph

Package

Name
ceph
Purl
pkg:bitnami/ceph

Severity

  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
14.2.21

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ceph/BIT-ceph-2020-1759.json"