Описание
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
An information-disclosure flaw was found in the way Heketi logs sensitive information. This flaw allows an attacker with local access to the Heketi server, to read potentially sensitive information, such as gluster-block passwords.
Отчет
The version of heketi shipped with Red Hat Gluster Storage 3 does not filter out gluster-block volume passwords, hence affected by this vulnerability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-efs-provisioner-rhel7 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-hyperkube-rhel9 | Will not fix | ||
| Native Client for RHEL 7 for Red Hat Storage | heketi | Fixed | RHSA-2020:4143 | 30.09.2020 |
| Red Hat Gluster Storage 3.5 for RHEL 7 | gluster-block | Fixed | RHSA-2020:4143 | 30.09.2020 |
| Red Hat Gluster Storage 3.5 for RHEL 7 | heketi | Fixed | RHSA-2020:4143 | 30.09.2020 |
| Red Hat Gluster Storage 3.5 for RHEL 7 | tcmu-runner | Fixed | RHSA-2020:4143 | 30.09.2020 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-cluster-autoscaler | Fixed | RHSA-2020:5633 | 24.02.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
An information-disclosure flaw was found in the way Heketi before 10.1 ...
EPSS
5.5 Medium
CVSS3