First published: Tue Oct 27 2020(Updated: )
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ceph-ansible | <0:4.0.41-1.el8c | 0:4.0.41-1.el8c |
redhat/ceph-ansible | <4.0.41 | 4.0.41 |
Ceph Ceph-ansible | =4.0.41 | |
Redhat Ceph Storage | =3.0 | |
Redhat Ceph Storage | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25677.
The title of the vulnerability is 'A flaw was found in Ceph-ansible where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.'
The software affected by this vulnerability is Ceph-ansible v4.0.41.
The severity of CVE-2020-25677 is medium.
To fix the vulnerability, update Ceph-ansible to version 4.0.41 or apply the appropriate security patches.