Описание
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
A flaw was found in Ceph where Ceph stores mgr module passwords in clear text. This issue can be found by searching the mgr logs for Grafana and dashboard, with passwords visible. The highest threat from this vulnerability is to confidentiality.
Отчет
- Red Hat Ceph Storage 4 is affected by this flaw, with the passwords visible under sudo. Red Hat Ceph Storage 3 is not affected by this flaw, and does not log passwords by default.
- Red Hat OpenShift Container Storage (RHOCS) 4 shipped Ceph package for the usage of RHOCS 4.2 only, that has reached End Of Life. Hence, the Ceph package is no longer used and supported with the release of RHOCS 4.3.
- Red Hat OpenStack Platform deployments use the Ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 2 | ceph | Out of support scope | ||
| Red Hat Ceph Storage 3 | ceph | Not affected | ||
| Red Hat Enterprise Linux 8 | ceph | Not affected | ||
| Red Hat Enterprise Linux 9 | ceph | Affected | ||
| Red Hat Openshift Container Storage 4 | ceph | Out of support scope | ||
| Red Hat OpenStack Platform 13 (Queens) | ceph | Will not fix | ||
| Red Hat Ceph Storage 4.2 | ceph | Fixed | RHSA-2021:1452 | 28.04.2021 |
| Red Hat Ceph Storage 4.2 | ceph-ansible | Fixed | RHSA-2021:1452 | 28.04.2021 |
| Red Hat Ceph Storage 4.2 | gperftools | Fixed | RHSA-2021:1452 | 28.04.2021 |
| Red Hat Ceph Storage 4.2 | tcmu-runner | Fixed | RHSA-2021:1452 | 28.04.2021 |
Показывать по
Дополнительная информация
Статус:
4.4 Medium
CVSS3
Связанные уязвимости
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
A flaw was found in ceph in versions prior to 16.y.z where ceph stores ...
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
4.4 Medium
CVSS3