Use of Hard-coded Credentials Affecting ceph-ansible package, versions *


Severity

Recommended
0.0
high
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
1.27% (66th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-CEPHANSIBLE-4394722
  • published26 Mar 2023
  • disclosed22 Jan 2019

Introduced: 22 Jan 2019

CVE-2020-1716  (opens in a new tab)
CWE-798  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:8 ceph-ansible.

NVD Description

Note: Versions mentioned in the description apply only to the upstream ceph-ansible package and not the ceph-ansible package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

CVSS Base Scores

version 3.1