漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MicroCeph path traversal issue in the remote-import API
Vulnerability Description
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement. This would allow daemon disruption and pollution of the cluster state.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H
Vulnerability Type
相对路径遍历
Vulnerability Title
Canonical MicroCeph 路径遍历漏洞
Vulnerability Description
Canonical MicroCeph是英国Canonical公司开源的一个轻量级分布式存储集群管理平台。 Canonical MicroCeph存在路径遍历漏洞,该漏洞源于remote-import API中的路径遍历问题,可能导致持有可信集群mTLS证书或加入令牌的攻击者操纵/var/snap/microceph中的文件,造成守护进程中断和集群状态污染。
CVSS Information
N/A
Vulnerability Type
N/A