Description
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-8677 | Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable. |
Ubuntu USN |
USN-4035-1 | Ceph vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T10:39:57.643Z
Reserved: 2018-09-11T00:00:00.000Z
Link: CVE-2018-16889
No data.
Status : Modified
Published: 2019-01-28T14:29:00.220
Modified: 2024-11-21T03:53:32.573
Link: CVE-2018-16889
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN