CVE-2020-10763
Last modified
CVE-2020-10763 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Heketi Project | Heketi | < 10.1.0 |
| Redhat | Gluster Storage | 3.0 |
| Redhat | Gluster Storage | 3.5 |
| Redhat | Openshift Container Platform | 4.0 |
| Redhat | Enterprise Linux | 7.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1845387Issue Tracking, Third Party Advisory
- https://github.com/heketi/heketi/releases/tag/v10.1.0Release Notes, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1845387Issue Tracking, Third Party Advisory
- https://github.com/heketi/heketi/releases/tag/v10.1.0Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10763?
How severe is CVE-2020-10763?
How do I fix CVE-2020-10763?
Are you affected by CVE-2020-10763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
