CVE-2020-1716
published 2021-05-28CVE-2020-1716: A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.27%
66.8th percentile
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ceph | ceph-ansible | <= 5.0.3 | — |
| ceph | ceph-ansible | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v27v-7hmw-76p2: A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph se
ghsa_unreviewed·2022-05-24
CVE-2020-1716 [HIGH] CWE-798 GHSA-v27v-7hmw-76p2: A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph se
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.
Red Hat
ceph-ansible: hard coded credential in ceph-ansible playbook
vendor_redhat·2019-01-22·CVSS 8.8
CVE-2020-1716 [HIGH] CWE-798 ceph-ansible: hard coded credential in ceph-ansible playbook
ceph-ansible: hard coded credential in ceph-ansible playbook
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clu
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25664 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
bugzilla·2020-10-26·CVSS 6.1
CVE-2020-25664 [MEDIUM] CVE-2020-25664 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
CVE-2020-25664 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
In ImageMagick, there is a heap-buffer-overflow at MagickCore/quantum-private.h:227:12 in PopShortPixel.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1716
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/1f450bb5ba53d275de6d1cd086c98a0b549ad393
Discussion:
Flaw summary:
In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data int
Bugzilla
CVE-2020-1716 ceph-ansible: hard coded credential in ceph-ansible playbook [fedora-30]
bugzilla·2020-03-13·CVSS 8.8
CVE-2020-1716 [HIGH] CVE-2020-1716 ceph-ansible: hard coded credential in ceph-ansible playbook [fedora-30]
CVE-2020-1716 ceph-ansible: hard coded credential in ceph-ansible playbook [fedora-30]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-30.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to f
Bugzilla
CVE-2020-1716 ceph-ansible: hard coded credential in ceph-ansible playbook
bugzilla·2020-01-28·CVSS 8.8
CVE-2020-1716 [HIGH] CVE-2020-1716 ceph-ansible: hard coded credential in ceph-ansible playbook
CVE-2020-1716 ceph-ansible: hard coded credential in ceph-ansible playbook
A vulnerability was found in ceph-ansible, where hard-coded passwords were found in roles/ceph-defaults/defaults/main.yml.
Reference:
https://github.com/ceph/ceph-ansible/blob/bb3eae0c8033dc0ffbee44f490f6ad483bd109b9/roles/ceph-defaults/defaults/main.yml
Discussion:
upstream fix
https://github.com/ceph/ceph-ansible/pull/4998
---
Mitigation:
Change and use strong passwords in ceph-ansible playbook
- https://github.com/ceph/ceph-ansible/blob/v4.0.14/roles/ceph-defaults/defaults/main.yml#L701
- https://github.com/ceph/ceph-ansible/blob/v4.0.14/roles/ceph-defaults/defaults/main.yml#L711
---
Acknowledgments:
Name: Sarthak Srivastava
---
Statement:
The version of ceph-ansible included in Red Hat OpenStack 1
2021-05-28
Published