CVE-2022-0670
NixOS vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2022-0670) was discovered in OpenStack Manila's integration with Ceph File system shares. The flaw, which received a CVSS v3.1 base score of 9.1 (Critical), affects systems where OpenStack Manila is used to export native CephFS and were upgraded from Nautilus (or earlier) to a later major version. The vulnerability was fixed in RHCS 5.2 and Ceph 17.2.2 (NVD, Ceph Blog).

Technical details

The vulnerability exists in the 'volumes' plugin within Ceph Manager, which is responsible for managing Ceph File System subvolumes used by OpenStack Manila services. The flaw enables a share owner to gain unauthorized access to arbitrary portions of the CephFS filesystem hierarchy, instead of being properly restricted to their own subvolumes. This vulnerability specifically impacts OpenStack Manila clusters that provided native CephFS access to their users (Ceph Blog).

Impact

The vulnerability allows an attacker to compromise both the confidentiality and integrity of the file system. Specifically, it enables the owner of a Ceph File system share to read and write to any Manila share or the entire file system, significantly breaching the intended access controls (NVD).

Mitigation and workarounds

The vulnerability has been fixed in RHCS 5.2 and Ceph 17.2.2. Administrators of affected systems should update to these versions or later. Additionally, administrators who are concerned about potential impact should audit their CephX keys in their cluster for proper path restrictions (Ceph Blog).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox_esr
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management