Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9w4f-3v37-6f75

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 1.2
CVSS3: 4

Описание

ceph-deploy allows local users to obtain sensitive information by reading the file

ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

Пакеты

Наименование

ceph-deploy

pip
Затронутые версииВерсия исправления

< 1.5.23

1.5.23

EPSS

Процентиль: 31%
0.00379
Низкий

1.2 Low

CVSS4

4 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 11 лет назад

ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

redhat
больше 11 лет назад

ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

nvd
около 11 лет назад

ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

debian
около 11 лет назад

ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.cl ...

EPSS

Процентиль: 31%
0.00379
Низкий

1.2 Low

CVSS4

4 Medium

CVSS3

Дефекты

CWE-200