A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1892108 Issue Tracking Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2020-12-08T00:02:25

Updated: 2021-02-23T18:41:04

Reserved: 2020-09-16T00:00:00


Link: CVE-2020-25677

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-12-08T01:15:12.070

Modified: 2021-03-04T18:49:09.047


Link: CVE-2020-25677

JSON object: View

cve-icon Redhat Information

No data.

CWE