Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10762

Опубликовано: 24 нояб. 2020
Источник: nvd
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:gluster-block:*:*:*:*:*:*:*:*
Версия до 0.5.1 (исключая)

EPSS

Процентиль: 8%
0.0003
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-732
CWE-532

Связанные уязвимости

CVSS3: 5.5
redhat
больше 5 лет назад

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

github
больше 3 лет назад

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

EPSS

Процентиль: 8%
0.0003
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-732
CWE-532