QID 198423
Date Published: 2021-06-30
QID 198423: Ubuntu Security Notification for Ceph vulnerabilities (USN-4998-1)
It was discovered that in some situations Ceph logged passwords from the mgr module in clear text.
It was discovered that user credentials in Ceph could be manipulated in certain environments.
It was discovered that the Ceph dashboard was susceptible to a cross-site scripting attack.
It was discovered that Ceph contained an authentication flaw, leading to key reuse.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An attacker could use this to expose sensitive information. (CVE-2020-25678)
An attacker could use this to gain unintended access. (CVE-2020-27781)
An attacker could use this to expose sensitive information or gain unintended access. (CVE-2020-27839)
An attacker could use this to cause a denial of service or possibly impersonate another user. (CVE-2021-20288)
- USN-4998-1 -
usn.ubuntu.com/4998-1
CVEs related to QID 198423
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4998-1 | Ubuntu Linux |
|