CVE-2020-25677
published 2020-12-08CVE-2020-25677: A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.21%
11.4th percentile
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ceph | ceph-ansible | — | — |
| ceph | ceph-ansible | — | — |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-637g-65xr-xr73: Ceph-ansible 4
ghsa_unreviewed·2022-05-24
CVE-2020-25677 [MEDIUM] CWE-312 GHSA-637g-65xr-xr73: Ceph-ansible 4
Ceph-ansible 4.0.34.1 creates /etc/ceph/iscsi-gateway.conf with insecure default permissions, allowing any user to read the sensitive information within.
Red Hat
ceph-ansible: insecure ownership on /etc/ceph/iscsi-gateway.conf configuration file
vendor_redhat·2020-11-23·CVSS 5.5
CVE-2020-25677 [MEDIUM] CWE-312 ceph-ansible: insecure ownership on /etc/ceph/iscsi-gateway.conf configuration file
ceph-ansible: insecure ownership on /etc/ceph/iscsi-gateway.conf configuration file
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
A flaw was found in Ceph-ansible where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
Statement: Red Hat OpenStack Platform 13 ships the flawed code, however RHOSP does not deploy ceph-iscsi-gw role in any supported scenario. For this reason, a ceph
No detection rules found.
No public exploits indexed.
2020-12-08
Published