A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1892109 | Issue Tracking Patch | 
| https://tracker.ceph.com/issues/37503 | Patch Vendor Advisory | 
| https://security.gentoo.org/glsa/202105-39 | Third Party Advisory | 
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OQTBKVXVYP7GPQNZ5VASOIJHMLK7727M/ | 
Information
                Published : 2021-01-08 10:15
Updated : 2023-02-12 15:40
NVD link : CVE-2020-25678
Mitre link : CVE-2020-25678
JSON object : View
CWE
                
                    
                        
                        CWE-312
                        
            Cleartext Storage of Sensitive Information
Products Affected
                fedoraproject
- fedora
redhat
- ceph_storage
- ceph


