CVE-2018-16889 PUBLISHED

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

EPSS 0.07% · 20.8th percentile

Risk Scores

EPSS Score
0.07%
20.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSceph0, 12.2.0-0ubuntu1, 12.2.1-0ubuntu1
Ubuntu:16.04:LTSceph10.1.0-0ubuntu1, 10.1.1-0ubuntu1, 10.1.2-0ubuntu1

Timeline

References

Open in Interactive Console →