Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1716

Опубликовано: 28 мая 2021
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ceph:ceph-ansible:*:*:*:*:*:*:*:*
Версия до 5.0.3 (включая)

EPSS

Процентиль: 69%
0.0063
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.8
redhat
больше 6 лет назад

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

rocky
около 5 лет назад

Important: Rocky Enterprise Software Foundation Ceph Storage 4.1 security, bug fix, and enhancement update

github
около 3 лет назад

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

EPSS

Процентиль: 69%
0.0063
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-798