VDB
CVE-2020-1716
CVE-2020-1716
PUBLISHED
CVSS 8.800000190734863 HIGH
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.
EPSS 1.27% · 67.0th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.27%
67.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ceph | ceph-ansible | 0 |
| n/a | ceph-ansible | * |
Timeline
- May 28, 2021 CVE Published
- May 29, 2021 EPSS Score
- Jul 31, 2021 EPSS Score
- Sep 30, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 31, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jun 2, 2022 EPSS Score
- Aug 3, 2022 EPSS Score
- Oct 4, 2022 EPSS Score
- Dec 4, 2022 EPSS Score