CVE-2020-10763 heketi: gluster-block volume password details available in logs

Related Vulnerabilities: CVE-2020-10763  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
CVE-2020-10763 heketi: gluster-block volume password details available in logs

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Hardik Vyas &lt;hvyas () redhat com&gt;

Date: Wed, 30 Sep 2020 20:40:59 +0530

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Hello,

An information-disclosure flaw was found in the way Heketi logs sensitive
information.
This flaw allows an attacker with local access to the Heketi server, to
read potentially
sensitive information, such as gluster-block passwords.

CVE-2020-10763 has been assigned for this flaw.

Upstream PR: https://github.com/heketi/heketi/pull/1790
Release: https://github.com/heketi/heketi/releases/tag/v10.1.0

Credit: Prasanna Kumar Kalever (Red Hat)

Thanks,
-- 

Hardik Vyas / Red Hat Product Security

BD48 C633 DE34 733A BBC3  3B72 8A14 AEBB D68B 9381
secalert () redhat com for urgent response
&lt;https://www.redhat.com&gt;

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

CVE-2020-10763 heketi: gluster-block volume password details available in logs Hardik Vyas (Sep 30)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->