VulnerabilityModified
CVE-2020-10763
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information.
MEDIUM 5.5EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- heketi project/heketi · redhat/gluster storage · redhat/openshift container platform · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1845387Issue Tracking, Third Party Advisory
- https://github.com/heketi/heketi/releases/tag/v10.1.0Release Notes, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1845387Issue Tracking, Third Party Advisory
- https://github.com/heketi/heketi/releases/tag/v10.1.0Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.