← back
CVE-2020-25677

CVE-2020-25677

EPSS 0.2%CWE-312
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Dec 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
Affected products
n/a · ceph-ansible

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →