Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16889

Опубликовано: 28 янв. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 5.5

Описание

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

РелизСтатусПримечание
bionic

released

12.2.11-0ubuntu0.18.04.1
cosmic

released

13.2.4+dfsg1-0ubuntu0.18.10.2
devel

released

14.2.1-0ubuntu1
disco

released

13.2.4+dfsg1-0ubuntu2.1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

released

10.2.11-0ubuntu0.16.04.2
esm-infra/bionic

released

12.2.11-0ubuntu0.18.04.1
esm-infra/xenial

released

10.2.11-0ubuntu0.16.04.2
precise/esm

not-affected

code not present
trusty

not-affected

code not present

Показывать по

EPSS

Процентиль: 42%
0.00536
Низкий

5 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 7 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

CVSS3: 5.5
nvd
больше 7 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

CVSS3: 5.5
debian
больше 7 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v ...

suse-cvrf
почти 7 лет назад

Security update for ceph

CVSS3: 7.5
github
больше 4 лет назад

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

EPSS

Процентиль: 42%
0.00536
Низкий

5 Medium

CVSS2

5.5 Medium

CVSS3