Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-1716 – A flaw was found in the ceph-ansible playbook where it contained hardcode

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1716

Reference (s):

  • https://bugzilla.redhat.com/show_bug.cgi?id=1795592
  • URL: https://bugzilla.redhat.com/show_bug.cgi?id=1795592
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4742 - Cross-site scripting (XSS) vulnerability in system/class_link.php in the

2021-current

CVE-2014-9837 - coders/pnm.c in ImageMagick 6.9.0-1 Beta and earlier allows remote attack

2021-current

CVE-2020-10446 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul