Database/Control plane, storage & DevOps
CephFS (via OpenStack Manila native driver): MULTI-TENANT ISOLATION: a Manila user can request access for an existing
Impact
MULTI-TENANT ISOLATION: a Manila user can request access for an existing CephFS identity and get that identity's credentials handed back, which means stealing another tenant's CephFS key. With that key the attacker mounts and reads/writes shares that belong to somebody else.
Who can reach it
Any tenant able to issue Manila share-access requests against a cluster using the native CephFS driver.
What to do
Apply the Ceph and Manila updates that scope credential creation to the requesting project, restart the manila-share and ceph-mgr volumes module, then rotate every CephFS auth ID that Manila created before the fix.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.