Project

General

Profile

Actions

Fix #7919

closed

mon: prevent clients with a read cap from reading the full keyring

Added by Greg Farnum about 10 years ago. Updated about 10 years ago.

Status:
Resolved
Priority:
Immediate
Category:
Monitor
Target version:
-
% Done:

0%

Source:
Community (user)
Tags:
Backport:
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

From the mailing list thread "[ceph-users] Security Hole?"

Hi everyone,

I'm running 0.72-2-1 on ubuntu. I just created a client with these ACLs:
caps: [mon] allow r
caps: [osd] allow rwx pool=cloudstack

So my cloudstack + KVM hypervisors work fine. However any client I can view full details of all the cluster's auth keys by running:
ceph --id cloudstack  --keyring=/etc/ceph/ceph.keyring auth list.

Is this a security hole in this version?

Actions

Also available in: Atom PDF