Hardcoded Password Vulnerability in Ceph Services by Red Hat
CVE-2020-1716
8.8HIGH
What is CVE-2020-1716?
A flaw exists in the ceph-ansible playbook involving hardcoded passwords used as defaults during the deployment of Ceph services. This vulnerability allows authenticated attackers to conduct brute-force attacks against Ceph deployments, enabling them to acquire administrator access through the Ceph dashboard. From there, attackers can perform actions such as reading, writing, or deleting Ceph clusters and altering cluster configurations.
Affected Version(s)
ceph-ansible ceph-ansible 6.0.0alpha1
