CVE-2020-25678
Summary
| CVE | CVE-2020-25678 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-08 18:15:00 UTC |
| Updated | 2023-10-23 19:15:00 UTC |
| Description | A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Bug #37503: Audit log: mgr module passwords set on CLI written as plaintext in log files - Ceph - Ceph |
MISC |
tracker.ceph.com |
Patch, Vendor Advisory |
| [SECURITY] [DLA 3629-1] ceph security update |
MISC |
lists.debian.org |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| 1892109 – (CVE-2020-25678) CVE-2020-25678 ceph: mgr modules' passwords are in clear text in mgr logs |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch |
| Ceph: Multiple vulnerabilities (GLSA 202105-39) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 33 Update: ceph-15.2.9-1.fc33 - package-announce - Fedora Mailing-Lists |
MISC |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: ceph-15.2.9-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174881 SUSE Enterprise Linux Security Update for ceph (SUSE-SU-2021:1108-1)
- 174975 SUSE Enterprise Linux Security Update for ceph (SUSE-SU-2021:1473-1)
- 198423 Ubuntu Security Notification for Ceph vulnerabilities (USN-4998-1)
- 239270 Red Hat Update for Red Hat Ceph Storage (RHSA-2021:1452)
- 281589 Fedora Security Update for ceph (FEDORA-2021-93ff9e9103)
- 6000278 Debian Security Update for ceph (DLA 3629-1)
- 670358 EulerOS Security Update for ceph (EulerOS-SA-2021-1866)
- 670860 EulerOS Security Update for ceph (EulerOS-SA-2021-1866)
- 710075 Gentoo Linux Ceph Multiple vulnerabilities (GLSA 202105-39)
- 750271 OpenSUSE Security Update for ceph (openSUSE-SU-2021:0544-1)