cvedb.io
CVE-2018-10861
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2018-07-10T14:29:00.213 · Last modified 2026-06-17T01:34:47.157

Summary

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

Affected products

ceph — ceph

Does this affect you?

Add your gear to cvedb and we'll alert you only when ceph ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.