Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25677

Опубликовано: 23 нояб. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

A flaw was found in Ceph-ansible where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

Отчет

Red Hat OpenStack Platform 13 ships the flawed code, however RHOSP does not deploy ceph-iscsi-gw role in any supported scenario. For this reason, a ceph-ansible update will not be provided at this time. Red Hat Ceph Storage 3 and 4 create /etc/ceph/iscsi-gateway.conf with the insecure permissions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2ceph-ansibleOut of support scope
Red Hat Ceph Storage 3ceph-ansibleAffected
Red Hat OpenStack Platform 13 (Queens)ceph-ansibleWill not fix
Red Hat Ceph Storage 4.2ceph-ansibleFixedRHSA-2021:008112.01.2021
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8ocs4/cephcsi-rhel8FixedRHBA-2021:030501.02.2021
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8ocs4/mcg-core-rhel8FixedRHBA-2021:030501.02.2021
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8ocs4/mcg-rhel8-operatorFixedRHBA-2021:030501.02.2021
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8ocs4/ocs-must-gather-rhel8FixedRHBA-2021:030501.02.2021
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8ocs4/ocs-operator-bundleFixedRHBA-2021:030501.02.2021
Red Hat OpenShift Container Storage 4.6.0 on RHEL-8ocs4/ocs-rhel8-operatorFixedRHBA-2021:030501.02.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=1892108ceph-ansible: insecure ownership on /etc/ceph/iscsi-gateway.conf configuration file

EPSS

Процентиль: 5%
0.0002
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 5 лет назад

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

github
больше 3 лет назад

Ceph-ansible 4.0.34.1 creates /etc/ceph/iscsi-gateway.conf with insecure default permissions, allowing any user to read the sensitive information within.

EPSS

Процентиль: 5%
0.0002
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2020-25677