Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4053

Опубликовано: 21 мая 2015
Источник: redhat
CVSS2: 4.3

Описание

The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

It was discovered that ceph-deploy, a utility for deploying Red Hat Ceph Storage, would create the keyring file with world readable permissions, which could possibly allow a local user to obtain authentication credentials from the keyring file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.1ceph-deployWill not fix
Red Hat Ceph Storage 1.3ceph-deployNot affected
Red Hat Ceph Storage 1.2 for CentOSFixedRHSA-2015:163117.08.2015
Red Hat Ceph Storage 1.2 for RHEL 6ceph-deployFixedRHSA-2015:109211.06.2015
Red Hat Ceph Storage 1.2 for RHEL 7ceph-deployFixedRHSA-2015:109211.06.2015
Red Hat Ceph Storage 1.2 for UbuntuFixedRHSA-2015:157907.08.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1224129ceph-deploy admin command copies keyring file to /etc/ceph which is world readable

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

nvd
больше 10 лет назад

The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

debian
больше 10 лет назад

The admin command in ceph-deploy before 1.5.25 uses world-readable per ...

github
больше 3 лет назад

ceph-deploy uses world-readable permissions on client.admin key

4.3 Medium

CVSS2