RHSA-2024:3925CriticalCVSS 9.8

Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security, enhancements, and bug fix update

Published
June 14, 2024
Last Modified
August 24, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2023-3128 — grafana: account takeover possible when using Azure AD OAuth CVE-2023-4822 — grafana: incorrect assessment of permissions across organizations CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

🎯 Affected products200

  • Red Hat Ceph Storage 7.1 Tools
  • ceph-2:18.2.1-194.el8cp.src as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-2:18.2.1-194.el9cp.src as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-2:18.2.1-194.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-2:18.2.1-194.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-2:18.2.1-194.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-2:18.2.1-194.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-2:18.2.1-194.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-debuginfo-2:18.2.1-194.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-debuginfo-2:18.2.1-194.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-debuginfo-2:18.2.1-194.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-debuginfo-2:18.2.1-194.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-base-debuginfo-2:18.2.1-194.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-2:18.2.1-194.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-2:18.2.1-194.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-2:18.2.1-194.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-2:18.2.1-194.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-2:18.2.1-194.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-debuginfo-2:18.2.1-194.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-debuginfo-2:18.2.1-194.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-debuginfo-2:18.2.1-194.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-debuginfo-2:18.2.1-194.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-common-debuginfo-2:18.2.1-194.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debuginfo-2:18.2.1-194.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debuginfo-2:18.2.1-194.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debuginfo-2:18.2.1-194.el9cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debuginfo-2:18.2.1-194.el9cp.s390x as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debuginfo-2:18.2.1-194.el9cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debugsource-2:18.2.1-194.el8cp.ppc64le as a component of Red Hat Ceph Storage 7.1 Tools
  • ceph-debugsource-2:18.2.1-194.el8cp.x86_64 as a component of Red Hat Ceph Storage 7.1 Tools
  • +170 more not shown

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Workaround: We recommend disabling Active Directory in the Grafana configuration file until a fix is provided. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.

🔗 References (251)