CVE-2020-25677: Medium severity ceph vulnerability
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
Other sources
A flaw was found in Ceph-ansible where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
ceph-ansible creates /etc/ceph/iscsi-gateway.conf with insecure ownership. This file contains sensitive information that can be read by any user on the system.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-25677.
What is the title of the vulnerability?
The title of the vulnerability is 'A flaw was found in Ceph-ansible where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.'
What software is affected by this vulnerability?
The software affected by this vulnerability is Ceph-ansible v4.0.41.
What is the severity of CVE-2020-25677?
The severity of CVE-2020-25677 is medium.
How can I fix the vulnerability?
To fix the vulnerability, update Ceph-ansible to version 4.0.41 or apply the appropriate security patches.