CVE-2020-25678
low-risk
Published 2021-01-08
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
Do I need to act?
-
0.01% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.4/10
Medium
LOCAL
/ LOW complexity
Affected Products (3)
Affected Vendors
References (10)
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1892109
Third Party Advisory
https://security.gentoo.org/glsa/202105-39
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=1892109
Third Party Advisory
https://security.gentoo.org/glsa/202105-39
24
/ 100
low-risk
Severity
15/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
9/34 · Low