A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ceph-osd-debuginfoUpgrade ceph-selinuxUpgrade python3-cephfsUpgrade nfs-ganesha-vfsUpgrade python3-ceph-argparseUpgrade cockpit-ceph-installerUpgrade ceph-ansibleUpgrade ceph-test-debuginfoUpgrade python3-rgw-debuginfoUpgrade ceph-radosgwUpgrade ceph-fuseUpgrade nfs-ganesha-rados-urlsUpgrade libradosstriper1Upgrade ceph-radosgw-debuginfoUpgrade ceph-base-debuginfoUpgrade ceph-mdsUpgrade python-rgwUpgrade python3-cephfs-debuginfoUpgrade ceph-debugsourceUpgrade python3-rbdUpgrade nfs-ganesha-cephUpgrade nfs-ganesha-rados-graceUpgrade librbd-develUpgrade librgw2Upgrade libradosstriper1-debuginfoUpgrade ceph-mon-debuginfoUpgrade ceph-common-debuginfoUpgrade ceph-mgr-debuginfoUpgrade libradospp-develUpgrade libntirpc-debuginfoUpgrade nfs-ganesha-ceph-debuginfoUpgrade python-ceph-argparseUpgrade python-cephfsUpgrade python3-rados-debuginfoUpgrade nfs-ganesha-rgwUpgrade rbd-mirror-debuginfoUpgrade rbd-mirrorUpgrade python3-rgwUpgrade ceph-baseUpgrade nfs-ganesha-debugsourceUpgrade nfs-ganesha-rados-grace-debuginfoUpgrade rbd-nbdUpgrade nfs-ganeshaUpgrade libcephfs2-debuginfoUpgrade ceph-fuse-debuginfoUpgrade ceph-grafana-dashboardsUpgrade librgw2-debuginfoUpgrade rbd-fuse-debuginfoUpgrade nfs-ganesha-selinuxUpgrade nfs-ganesha-rgw-debuginfoUpgrade nfs-ganesha-rados-urls-debuginfoUpgrade nfs-ganesha-proxyUpgrade libcephfs-develUpgrade ceph-mds-debuginfoUpgrade librados-devel-debuginfoUpgrade libntirpc-debugsourceUpgrade libntirpcUpgrade ceph-debuginfoUpgrade ceph-commonUpgrade ansible-runner-serviceUpgrade libcephfs2Upgrade rbd-nbd-debuginfoUpgrade nfs-ganesha-vfs-debuginfoUpgrade nfs-ganesha-proxy-debuginfoUpgrade librgw-develUpgrade python3-radosUpgrade python3-rbd-debuginfoUpgrade librados-develUpgrade nfs-ganesha-debuginfo | Jan 14, 2021 | Dec 8, 2020 |
| Redhat_linux | — | Upgrade nfs-ganesha-proxy-debuginfoUpgrade python3-rbd-debuginfoUpgrade nfs-ganesha-ceph-debuginfoUpgrade librados-devel-debuginfoUpgrade ceph-baseUpgrade ceph-base-debuginfoUpgrade ceph-mgr-debuginfoUpgrade nfs-ganesha-cephUpgrade rbd-mirrorUpgrade librgw-develUpgrade libcephfs2Upgrade libntirpc-debuginfoUpgrade ceph-grafana-dashboardsUpgrade librados-develUpgrade rbd-nbd-debuginfoUpgrade nfs-ganeshaUpgrade libradosstriper1-debuginfoUpgrade python3-rgw-debuginfoUpgrade ceph-radosgw-debuginfoUpgrade libradospp-develUpgrade nfs-ganesha-rados-grace-debuginfoUpgrade nfs-ganesha-debugsourceUpgrade ceph-debuginfoUpgrade python3-rbdUpgrade cockpit-ceph-installerUpgrade nfs-ganesha-vfsUpgrade libcephfs-develUpgrade nfs-ganesha-rgw-debuginfoUpgrade nfs-ganesha-rados-urls-debuginfoUpgrade libntirpcUpgrade libcephfs2-debuginfoUpgrade rbd-mirror-debuginfoUpgrade nfs-ganesha-debuginfoUpgrade ceph-mds-debuginfoUpgrade nfs-ganesha-rados-graceUpgrade nfs-ganesha-rados-urlsUpgrade python3-ceph-argparseUpgrade libntirpc-debugsourceUpgrade nfs-ganesha-selinuxUpgrade nfs-ganesha-vfs-debuginfoUpgrade python3-rados-debuginfoUpgrade librbd-develUpgrade ceph-commonUpgrade librgw2Upgrade python3-cephfsUpgrade python-rgwUpgrade ceph-fuseUpgrade ceph-mon-debuginfoUpgrade python-ceph-argparseUpgrade ceph-selinuxUpgrade rbd-fuse-debuginfoUpgrade ceph-common-debuginfoUpgrade nfs-ganesha-rgwUpgrade python3-cephfs-debuginfoUpgrade ceph-fuse-debuginfoUpgrade python3-rgwUpgrade ceph-radosgwUpgrade ceph-test-debuginfoUpgrade python-cephfsUpgrade rbd-nbdUpgrade ceph-debugsourceUpgrade python3-radosUpgrade ceph-ansibleUpgrade ceph-osd-debuginfoUpgrade ceph-mdsUpgrade libradosstriper1Upgrade librgw2-debuginfoUpgrade ansible-runner-serviceUpgrade nfs-ganesha-proxy | Jan 14, 2021 | Dec 8, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub