Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16889

Опубликовано: 28 янв. 2019
Источник: ubuntu
Приоритет: low
CVSS2: 5
CVSS3: 5.5

Описание

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

РелизСтатусПримечание
bionic

released

12.2.11-0ubuntu0.18.04.1
cosmic

released

13.2.4+dfsg1-0ubuntu0.18.10.2
devel

released

14.2.1-0ubuntu1
disco

released

13.2.4+dfsg1-0ubuntu2.1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

released

12.2.11-0ubuntu0.18.04.1
esm-infra/xenial

released

10.2.11-0ubuntu0.16.04.2
precise/esm

not-affected

code not present
trusty

not-affected

code not present
trusty/esm

not-affected

code not present

Показывать по

5 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
около 7 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

CVSS3: 5.5
nvd
около 7 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

CVSS3: 5.5
debian
около 7 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v ...

suse-cvrf
больше 6 лет назад

Security update for ceph

CVSS3: 7.5
github
больше 3 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

5 Medium

CVSS2

5.5 Medium

CVSS3