Vulnerabilities > Ceph > Ceph Ansible > 4.0.41

DATE CVE VULNERABILITY TITLE RISK
2021-05-28 CVE-2020-1716 Use of Hard-coded Credentials vulnerability in Ceph Ceph-Ansible
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services.
network
low complexity
ceph CWE-798
critical
9.0
2020-12-08 CVE-2020-25677 Cleartext Storage of Sensitive Information vulnerability in multiple products
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.
local
low complexity
ceph redhat CWE-312
2.1