suse · CVE-2018-1128

Quick triage

Priority: high Published: 2021-05-30 14:06:58 UTC Updated: 2026-04-17 15:43:53 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-1128 severity important: SUSE including 508 source package names (ceph, ceph-10.2.11+git.1531487710.3a12911a2e-12.14.2, …), 873 product×package rows across 90 product lines (Image SLES12-SP5-SAP-Azure-LI-BYOS-Production, Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production, … (90 product lines)): Fixed 688, Known Not Affected 185.

Description:

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

cvelogic Threat Intelligence