CVE-2018-16889

EUVD-2018-8677
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
redhatCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
redhatceph
𝑥
≤ 13.2.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ceph
bookworm
16.2.11+ds-2
fixed
bullseye
14.2.21-1
fixed
jessie
not-affected
sid
18.2.4+ds-7
fixed
stretch
postponed
trixie
18.2.4+ds-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ceph
bionic
Fixed 12.2.11-0ubuntu0.18.04.1
released
cosmic
Fixed 13.2.4+dfsg1-0ubuntu0.18.10.2
released
disco
Fixed 13.2.4+dfsg1-0ubuntu2.1
released
trusty
not-affected
xenial
Fixed 10.2.11-0ubuntu0.16.04.2
released