Описание
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 12.2.11-0ubuntu0.18.04.1 |
| cosmic | released | 13.2.4+dfsg1-0ubuntu0.18.10.2 |
| devel | released | 14.2.1-0ubuntu1 |
| disco | released | 13.2.4+dfsg1-0ubuntu2.1 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra/bionic | released | 12.2.11-0ubuntu0.18.04.1 |
| esm-infra/xenial | released | 10.2.11-0ubuntu0.16.04.2 |
| precise/esm | not-affected | code not present |
| trusty | not-affected | code not present |
| trusty/esm | not-affected | code not present |
Показывать по
5 Medium
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
Ceph does not properly sanitize encryption keys in debug logging for v ...
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
5 Medium
CVSS2
5.5 Medium
CVSS3