Unrated severityNVD Advisory· Published Jan 28, 2019· Updated Aug 5, 2024
CVE-2018-16889
CVE-2018-16889
Description
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.
Affected products
12- osv-coords11 versionspkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/ceph&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/ceph&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4
< 12.2.10+git.1549630712.bb089269ea-2.27.2+ 10 more
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 14.2.1.468+g994fd9e0cc-3.3.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 14.2.1.468+g994fd9e0cc-3.3.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- (no CPE)range: < 12.2.10+git.1549630712.bb089269ea-2.27.2
- The Ceph Project/cephv5Range: up to v13.2.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- access.redhat.com/errata/RHSA-2019:2538mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2019:2541mitrevendor-advisoryx_refsource_REDHAT
- usn.ubuntu.com/4035-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.securityfocus.com/bid/106528mitrevdb-entryx_refsource_BID
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.