2.1
CVSSv2

CVE-2020-10762

Published: 24/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An information-disclosure flaw was found in the way that gluster-block prior to 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat gluster-block

Vendor Advisories

Synopsis Moderate: OCS 311z async security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated OpenShift Container Storage packages fixing various security issues and other bugs are now available for Red Hat OpenShift Container Storage with 311z Async updateRed Hat ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-10762 gluster-block: information disclosure through world-readable gluster-block log files <!--X-Subject-Header-End-- ...