5.5
CVSSv3

CVE-2020-10763

Published: 24/11/2020 Updated: 02/12/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An information-disclosure flaw was found in the way Heketi prior to 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

heketi project heketi

redhat gluster storage 3.0

redhat gluster storage 3.5

redhat openshift container platform 4.0

redhat enterprise linux 7.0

Vendor Advisories

Synopsis Moderate: OCS 311z async security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated OpenShift Container Storage packages fixing various security issues and other bugs are now available for Red Hat OpenShift Container Storage with 311z Async updateRed Hat ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2020-10763 heketi: gluster-block volume password details available in logs <!--X-Subject-Header-End--> <!--X-Head-of-Messa ...