CVE-2015-3010 REJECTED

ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

EPSS 0.05% · 14.9th percentile

Risk Scores

EPSS Score
0.05%
14.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSceph-deploy0, 1.5.20-0ubuntu1, 1.5.31-0ubuntu1

Timeline

References

Open in Interactive Console →