A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
2020-12-08T01:15:12.070
2024-11-21T05:18:26.463
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ceph | ceph-ansible | 4.0.41 | Yes |
| Application | redhat | ceph_storage | 3.0 | Yes |
| Application | redhat | ceph_storage | 4.0 | Yes |