CVE-2020-25678

Name
CVE-2020-25678
Description
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1892109
Patch https://tracker.ceph.com/issues/37503
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQTBKVXVYP7GPQNZ5VASOIJHMLK7727M/
Third Party Advisory https://security.gentoo.org/glsa/202105-39

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:redhat:ceph:*:*:*:*:*:*:*:* ceph >= None < 16.2.0
cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:* ceph_storage == None == 4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ceph edge-community 15.2.8-r0 None possibly vulnerable
ceph edge-community 15.2.6-r0 None possibly vulnerable
ceph edge-community 14.2.9-r0 None possibly vulnerable
ceph edge-community 14.2.7-r0 None possibly vulnerable
ceph edge-community 14.2.3-r0 None possibly vulnerable