CVE-2020-25678

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
08/01/2021
Last modified:
23/10/2023

Description

A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:* 16.2.0 (excluding)
cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*