Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25678

Опубликовано: 23 нояб. 2020
Источник: redhat
CVSS3: 4.4

Описание

A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

A flaw was found in Ceph where Ceph stores mgr module passwords in clear text. This issue can be found by searching the mgr logs for Grafana and dashboard, with passwords visible. The highest threat from this vulnerability is to confidentiality.

Отчет

  • Red Hat Ceph Storage 4 is affected by this flaw, with the passwords visible under sudo. Red Hat Ceph Storage 3 is not affected by this flaw, and does not log passwords by default.
  • Red Hat OpenShift Container Storage (RHOCS) 4 shipped Ceph package for the usage of RHOCS 4.2 only, that has reached End Of Life. Hence, the Ceph package is no longer used and supported with the release of RHOCS 4.3.
  • Red Hat OpenStack Platform deployments use the Ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2cephOut of support scope
Red Hat Ceph Storage 3cephNot affected
Red Hat Enterprise Linux 8cephNot affected
Red Hat Enterprise Linux 9cephAffected
Red Hat Openshift Container Storage 4cephOut of support scope
Red Hat OpenStack Platform 13 (Queens)cephWill not fix
Red Hat Ceph Storage 4.2cephFixedRHSA-2021:145228.04.2021
Red Hat Ceph Storage 4.2ceph-ansibleFixedRHSA-2021:145228.04.2021
Red Hat Ceph Storage 4.2gperftoolsFixedRHSA-2021:145228.04.2021
Red Hat Ceph Storage 4.2tcmu-runnerFixedRHSA-2021:145228.04.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=1892109ceph: mgr modules' passwords are in clear text in mgr logs

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 5 лет назад

A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

CVSS3: 4.4
nvd
около 5 лет назад

A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

CVSS3: 4.4
debian
около 5 лет назад

A flaw was found in ceph in versions prior to 16.y.z where ceph stores ...

CVSS3: 4.4
github
больше 3 лет назад

A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

suse-cvrf
почти 5 лет назад

Security update for ceph

4.4 Medium

CVSS3