PT-2019-9383 · Ceph+3 · Ceph+3
Sam Fowler
·
Published
2019-01-28
·
Updated
2023-02-13
·
CVE-2018-16889
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ceph versions up to v13.2.4
Description
The issue is related to the improper sanitization of encryption keys in debug logging for v4 auth, resulting in the leaking of encryption key information in log files via plaintext.
Recommendations
For versions up to v13.2.4, update to a version later than v13.2.4 to resolve the issue.
As a temporary workaround, consider disabling debug logging for v4 auth to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Insertion into Log File
RCE
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Ceph
Suse
Ubuntu