Insecure File Permissions in Ceph-ansible Affects Red Hat
CVE-2020-25677
5.5MEDIUM
What is CVE-2020-25677?
A vulnerability exists in Ceph-ansible version 4.0.41, where the tool improperly sets file permissions for the configuration file located at /etc/ceph/iscsi-gateway.conf. This misconfiguration allows any local user to access sensitive data contained within the file. Such exposure poses a significant risk to confidentiality, as unauthorized users could potentially read and exploit sensitive information.
Affected Version(s)
ceph-ansible ceph-ansible-4.0.41
