CVE-2020-10763
published 2020-11-24CVE-2020-10763: An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.41%
33.5th percentile
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | heketi_heketi | >= 0 < 10.1.0 | 10.1.0 |
| heketi_project | heketi | < 10.1.0 | 10.1.0 |
| heketi_project | heketi | — | — |
| redhat | enterprise_linux | — | — |
| redhat | gluster_storage | — | — |
| redhat | gluster_storage | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Heketi logs sensitive information
osv·2022-05-24
CVE-2020-10763 [MEDIUM] Heketi logs sensitive information
Heketi logs sensitive information
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
GHSA
Heketi logs sensitive information
ghsa·2022-05-24
CVE-2020-10763 [MEDIUM] CWE-532 Heketi logs sensitive information
Heketi logs sensitive information
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
Red Hat
heketi: gluster-block volume password details available in logs
vendor_redhat·2020-09-30·CVSS 5.5
CVE-2020-10763 [MEDIUM] CWE-532 heketi: gluster-block volume password details available in logs
heketi: gluster-block volume password details available in logs
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
An information-disclosure flaw was found in the way Heketi logs sensitive information. This flaw allows an attacker with local access to the Heketi server, to read potentially sensitive information, such as gluster-block passwords.
Statement: The version of heketi shipped with Red Hat Gluster Storage 3 does not filter out gluster-block volume passwords, hence affected by this vulnerability.
Mitigation: Mitigation for this issue is either not available or the currently available optio
No detection rules found.
No public exploits indexed.
2020-11-24
Published