CVE-2020-25678
Description
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
Risk Information
Base Score
4.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.015
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-ansible-4.0.49.2-1.el7cp.noarch.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-ansible-4.0.49.2-1.el8cp.noarch.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-base-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-base-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-common-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-common-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-debugsource-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-fuse-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-fuse-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-grafana-dashboards-14.2.11-147.el7cp.noarch.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-grafana-dashboards-14.2.11-147.el8cp.noarch.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-mds-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-mds-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-radosgw-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-radosgw-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-selinux-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update ceph-selinux-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update gperftools-debugsource-2.6.3-3.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update gperftools-libs-2.6.3-3.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libcephfs-devel-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libcephfs-devel-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libcephfs2-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libcephfs2-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librados-devel-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librados-devel-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librados2-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librados2-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libradospp-devel-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libradospp-devel-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libradosstriper1-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libradosstriper1-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librbd-devel-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librbd-devel-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librbd1-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librbd1-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librgw-devel-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librgw-devel-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librgw2-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update librgw2-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libtcmu-1.5.2-2.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update libtcmu-1.5.2-3.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python-ceph-argparse-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python-cephfs-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python-rados-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python-rbd-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python-rgw-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python3-ceph-argparse-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python3-cephfs-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python3-rados-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python3-rbd-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update python3-rgw-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update rbd-mirror-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update rbd-mirror-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update rbd-nbd-14.2.11-147.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update rbd-nbd-14.2.11-147.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update tcmu-runner-1.5.2-2.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:1452) Red Hat Ceph Storage security, bug fix, and enhancement Update tcmu-runner-1.5.2-3.el8cp.x86_64.rpm | Linux |
| distributed storage and file system (USN-4998-1) ceph_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-base_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-base_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-common_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-common_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234