PT-2020-12316 · Red Hat · Gluster-Block

Prasanna Kumar Kalever

·

Published

2020-11-24

·

Updated

2020-12-03

·

CVE-2020-10762

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions gluster-block versions prior to 0.5.1
Description An information-disclosure flaw was found in the way that gluster-block logs the output from gluster-block CLI operations, including recording passwords to the cmd history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.
Recommendations For versions prior to 0.5.1, update to version 0.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the cmd history.log file to minimize the risk of exploitation.

Fix

Insertion into Log File

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10762
RHSA-2020:4143

Affected Products

Gluster-Block