VDB

CVE-2020-1716

CVE-2020-1716 PUBLISHED CVSS 8.800000190734863 HIGH

A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.

EPSS 1.27% · 67.0th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.27%
67.0th percentile

Affected Products

VendorProductVersions
cephceph-ansible0
n/aceph-ansible*

Timeline

  • May 28, 2021 CVE Published
  • May 29, 2021 EPSS Score
  • Jul 31, 2021 EPSS Score
  • Sep 30, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 31, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jun 2, 2022 EPSS Score
  • Aug 3, 2022 EPSS Score
  • Oct 4, 2022 EPSS Score
  • Dec 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›