World-Readable Permissions in Ceph-Deploy Affects Admin Keyring Access
CVE-2015-4053

Currently unrated

Key Information:

Vendor

Ceph

Vendor
CVE Published:
8 June 2015

What is CVE-2015-4053?

Ceph-deploy versions prior to 1.5.25 have a vulnerability that results from insecure permissions on the /etc/ceph/ceph.client.admin.keyring file. This makes it accessible to all local users, enabling them to read sensitive information that should be restricted. This design flaw highlights the importance of implementing proper file permission controls to prevent unauthorized access to critical security credentials.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.