A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
References
Configurations
History
21 Nov 2024, 05:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1892109 - Issue Tracking, Patch | |
References | () https://lists.debian.org/debian-lts-announce/2023/10/msg00034.html - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQTBKVXVYP7GPQNZ5VASOIJHMLK7727M/ - | |
References | () https://security.gentoo.org/glsa/202105-39 - Third Party Advisory | |
References | () https://tracker.ceph.com/issues/37503 - Patch, Vendor Advisory |
23 Oct 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE |
Information
Published : 2021-01-08 18:15
Updated : 2024-11-21 05:18
NVD link : CVE-2020-25678
Mitre link : CVE-2020-25678
CVE.ORG link : CVE-2020-25678
JSON object : View
Products Affected
redhat
- ceph
- ceph_storage
fedoraproject
- fedora
CWE
CWE-312
Cleartext Storage of Sensitive Information