global_id

  1. t.lamprecht

    Ceph Nautilus and Octopus Security Update for "insecure global_id reclaim" CVE-2021-20288

    We released updates for all of our currently supported Ceph releases to fix a security issue where Ceph was not ensuring that reconnecting/renewing clients were presenting an existing ticket when reclaiming their global_id value. An attacker that was able to authenticate could claim a global_id...