← Vulnerability feed

Vulnerability record · CVE-2020-25677 · published 8 December 2020

CVE-2020-25677: Ceph-ansible cleartext storage of sensitive data vulnerability

Ceph · Ceph Ansible

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

5.5 CVSS 3.1 Medium EPSS 0.21% · top 89.6% CWE-312 · Cleartext storage of sensitive data
5.5CVSS 3.1 base score, v2 2.1
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=1892108 Issue TrackingPatchVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1892108 Issue TrackingPatchVendor Advisory

Track CVE-2020-25677 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed9.8CVE-2021-20236Zeromq classic buffer overflow vulnerabilityA flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by…EPSS 1.6%9.8CVE-2018-14649Redhat enterprise linux desktop command injection vulnerabilityIt was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by sett…EPSS 12%9.8CVE-2018-15727Grafana authentication bypass via forged remember-me cookieGrafana versions 2.x, 3.x, 4.x before 4.6.4 and 5.x before 5.2.3 allow authentication bypass because an attacker can generate a valid "remember me" c…EPSS 64%analysed9.1CVE-2022-0670Linuxfoundation ceph incorrect authorization vulnerabilityA flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…EPSS 1.2%9.1CVE-2021-4048Lapack project lapack out-of-bounds read vulnerabilityAn out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b…EPSS 2.6%9.1CVE-2019-14859Python-ecdsa project python-ecdsa improper verification of cryptographic signature vulnerabilityA flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this ver…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2020-25677), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.