ZeroHour

CVE-2020-25677

CVSS 3.1
5.5 medium
EPSS
<1%p12
Published
()
Modified
Description

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

Vendors
cephredhat
Products
ceph-ansible, ceph storage
Weakness
CWE-312
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.