Vulnerability Details CVE-2020-1716
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deploying Ceph services. Any authenticated attacker can abuse this flaw to brute-force Ceph deployments, and gain administrator access to Ceph clusters via the Ceph dashboard to initiate read, write, and delete Ceph clusters and also modify Ceph cluster configurations. Versions before ceph-ansible 6.0.0alpha1 are affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2020-1716
-
cpe:2.3:a:ceph:ceph-ansible:1.0.0
-
cpe:2.3:a:ceph:ceph-ansible:1.0.1
-
cpe:2.3:a:ceph:ceph-ansible:1.0.2
-
cpe:2.3:a:ceph:ceph-ansible:1.0.3
-
cpe:2.3:a:ceph:ceph-ansible:1.0.4
-
cpe:2.3:a:ceph:ceph-ansible:1.0.5
-
cpe:2.3:a:ceph:ceph-ansible:1.0.6
-
cpe:2.3:a:ceph:ceph-ansible:1.0.7
-
cpe:2.3:a:ceph:ceph-ansible:1.0.8
-
cpe:2.3:a:ceph:ceph-ansible:1.04
-
cpe:2.3:a:ceph:ceph-ansible:2.0
-
cpe:2.3:a:ceph:ceph-ansible:2.0.0
-
cpe:2.3:a:ceph:ceph-ansible:2.1.0
-
cpe:2.3:a:ceph:ceph-ansible:2.1.1
-
cpe:2.3:a:ceph:ceph-ansible:2.1.2
-
cpe:2.3:a:ceph:ceph-ansible:2.1.3
-
cpe:2.3:a:ceph:ceph-ansible:2.1.4
-
cpe:2.3:a:ceph:ceph-ansible:2.1.5
-
cpe:2.3:a:ceph:ceph-ansible:2.1.6
-
cpe:2.3:a:ceph:ceph-ansible:2.1.7
-
cpe:2.3:a:ceph:ceph-ansible:2.1.8
-
cpe:2.3:a:ceph:ceph-ansible:2.1.9
-
cpe:2.3:a:ceph:ceph-ansible:2.2.0
-
cpe:2.3:a:ceph:ceph-ansible:2.2.1
-
cpe:2.3:a:ceph:ceph-ansible:2.2.10
-
cpe:2.3:a:ceph:ceph-ansible:2.2.11
-
cpe:2.3:a:ceph:ceph-ansible:2.2.12
-
cpe:2.3:a:ceph:ceph-ansible:2.2.2
-
cpe:2.3:a:ceph:ceph-ansible:2.2.3
-
cpe:2.3:a:ceph:ceph-ansible:2.2.4
-
cpe:2.3:a:ceph:ceph-ansible:2.2.5
-
cpe:2.3:a:ceph:ceph-ansible:2.2.6
-
cpe:2.3:a:ceph:ceph-ansible:2.2.7
-
cpe:2.3:a:ceph:ceph-ansible:2.2.8
-
cpe:2.3:a:ceph:ceph-ansible:2.2.9
-
cpe:2.3:a:ceph:ceph-ansible:2.3.0
-
cpe:2.3:a:ceph:ceph-ansible:3.0.0
-
cpe:2.3:a:ceph:ceph-ansible:3.0.1
-
cpe:2.3:a:ceph:ceph-ansible:3.0.10
-
cpe:2.3:a:ceph:ceph-ansible:3.0.11
-
cpe:2.3:a:ceph:ceph-ansible:3.0.12
-
cpe:2.3:a:ceph:ceph-ansible:3.0.13
-
cpe:2.3:a:ceph:ceph-ansible:3.0.14
-
cpe:2.3:a:ceph:ceph-ansible:3.0.15
-
cpe:2.3:a:ceph:ceph-ansible:3.0.16
-
cpe:2.3:a:ceph:ceph-ansible:3.0.17
-
cpe:2.3:a:ceph:ceph-ansible:3.0.18
-
cpe:2.3:a:ceph:ceph-ansible:3.0.19
-
cpe:2.3:a:ceph:ceph-ansible:3.0.2
-
cpe:2.3:a:ceph:ceph-ansible:3.0.20
-
cpe:2.3:a:ceph:ceph-ansible:3.0.21
-
cpe:2.3:a:ceph:ceph-ansible:3.0.22
-
cpe:2.3:a:ceph:ceph-ansible:3.0.23
-
cpe:2.3:a:ceph:ceph-ansible:3.0.24
-
cpe:2.3:a:ceph:ceph-ansible:3.0.25
-
cpe:2.3:a:ceph:ceph-ansible:3.0.26
-
cpe:2.3:a:ceph:ceph-ansible:3.0.27
-
cpe:2.3:a:ceph:ceph-ansible:3.0.28
-
cpe:2.3:a:ceph:ceph-ansible:3.0.29
-
cpe:2.3:a:ceph:ceph-ansible:3.0.3
-
cpe:2.3:a:ceph:ceph-ansible:3.0.30
-
cpe:2.3:a:ceph:ceph-ansible:3.0.31
-
cpe:2.3:a:ceph:ceph-ansible:3.0.32
-
cpe:2.3:a:ceph:ceph-ansible:3.0.33
-
cpe:2.3:a:ceph:ceph-ansible:3.0.34
-
cpe:2.3:a:ceph:ceph-ansible:3.0.35
-
cpe:2.3:a:ceph:ceph-ansible:3.0.36
-
cpe:2.3:a:ceph:ceph-ansible:3.0.37
-
cpe:2.3:a:ceph:ceph-ansible:3.0.38
-
cpe:2.3:a:ceph:ceph-ansible:3.0.39
-
cpe:2.3:a:ceph:ceph-ansible:3.0.4
-
cpe:2.3:a:ceph:ceph-ansible:3.0.40
-
cpe:2.3:a:ceph:ceph-ansible:3.0.41
-
cpe:2.3:a:ceph:ceph-ansible:3.0.42
-
cpe:2.3:a:ceph:ceph-ansible:3.0.43
-
cpe:2.3:a:ceph:ceph-ansible:3.0.44
-
cpe:2.3:a:ceph:ceph-ansible:3.0.45
-
cpe:2.3:a:ceph:ceph-ansible:3.0.46
-
cpe:2.3:a:ceph:ceph-ansible:3.0.47
-
cpe:2.3:a:ceph:ceph-ansible:3.0.5
-
cpe:2.3:a:ceph:ceph-ansible:3.0.6
-
cpe:2.3:a:ceph:ceph-ansible:3.0.7
-
cpe:2.3:a:ceph:ceph-ansible:3.0.8
-
cpe:2.3:a:ceph:ceph-ansible:3.0.9
-
cpe:2.3:a:ceph:ceph-ansible:3.1.0
-
cpe:2.3:a:ceph:ceph-ansible:3.1.1
-
cpe:2.3:a:ceph:ceph-ansible:3.1.10
-
cpe:2.3:a:ceph:ceph-ansible:3.1.11
-
cpe:2.3:a:ceph:ceph-ansible:3.1.12
-
cpe:2.3:a:ceph:ceph-ansible:3.1.13
-
cpe:2.3:a:ceph:ceph-ansible:3.1.2
-
cpe:2.3:a:ceph:ceph-ansible:3.1.3
-
cpe:2.3:a:ceph:ceph-ansible:3.1.4
-
cpe:2.3:a:ceph:ceph-ansible:3.1.5
-
cpe:2.3:a:ceph:ceph-ansible:3.1.6
-
cpe:2.3:a:ceph:ceph-ansible:3.1.7
-
cpe:2.3:a:ceph:ceph-ansible:3.1.8
-
cpe:2.3:a:ceph:ceph-ansible:3.1.9
-
cpe:2.3:a:ceph:ceph-ansible:3.2.0
-
cpe:2.3:a:ceph:ceph-ansible:3.2.1
-
cpe:2.3:a:ceph:ceph-ansible:3.2.10
-
cpe:2.3:a:ceph:ceph-ansible:3.2.11
-
cpe:2.3:a:ceph:ceph-ansible:3.2.12
-
cpe:2.3:a:ceph:ceph-ansible:3.2.13
-
cpe:2.3:a:ceph:ceph-ansible:3.2.14
-
cpe:2.3:a:ceph:ceph-ansible:3.2.15
-
cpe:2.3:a:ceph:ceph-ansible:3.2.16
-
cpe:2.3:a:ceph:ceph-ansible:3.2.17
-
cpe:2.3:a:ceph:ceph-ansible:3.2.18
-
cpe:2.3:a:ceph:ceph-ansible:3.2.19
-
cpe:2.3:a:ceph:ceph-ansible:3.2.2
-
cpe:2.3:a:ceph:ceph-ansible:3.2.20
-
cpe:2.3:a:ceph:ceph-ansible:3.2.21
-
cpe:2.3:a:ceph:ceph-ansible:3.2.22
-
cpe:2.3:a:ceph:ceph-ansible:3.2.23
-
cpe:2.3:a:ceph:ceph-ansible:3.2.24
-
cpe:2.3:a:ceph:ceph-ansible:3.2.25
-
cpe:2.3:a:ceph:ceph-ansible:3.2.26
-
cpe:2.3:a:ceph:ceph-ansible:3.2.27
-
cpe:2.3:a:ceph:ceph-ansible:3.2.28
-
cpe:2.3:a:ceph:ceph-ansible:3.2.29
-
cpe:2.3:a:ceph:ceph-ansible:3.2.3
-
cpe:2.3:a:ceph:ceph-ansible:3.2.30
-
cpe:2.3:a:ceph:ceph-ansible:3.2.30.1
-
cpe:2.3:a:ceph:ceph-ansible:3.2.31
-
cpe:2.3:a:ceph:ceph-ansible:3.2.32
-
cpe:2.3:a:ceph:ceph-ansible:3.2.33
-
cpe:2.3:a:ceph:ceph-ansible:3.2.34
-
cpe:2.3:a:ceph:ceph-ansible:3.2.35
-
cpe:2.3:a:ceph:ceph-ansible:3.2.36
-
cpe:2.3:a:ceph:ceph-ansible:3.2.37
-
cpe:2.3:a:ceph:ceph-ansible:3.2.38
-
cpe:2.3:a:ceph:ceph-ansible:3.2.39
-
cpe:2.3:a:ceph:ceph-ansible:3.2.4
-
cpe:2.3:a:ceph:ceph-ansible:3.2.40
-
cpe:2.3:a:ceph:ceph-ansible:3.2.41
-
cpe:2.3:a:ceph:ceph-ansible:3.2.42
-
cpe:2.3:a:ceph:ceph-ansible:3.2.43
-
cpe:2.3:a:ceph:ceph-ansible:3.2.44
-
cpe:2.3:a:ceph:ceph-ansible:3.2.45
-
cpe:2.3:a:ceph:ceph-ansible:3.2.46
-
cpe:2.3:a:ceph:ceph-ansible:3.2.47
-
cpe:2.3:a:ceph:ceph-ansible:3.2.48
-
cpe:2.3:a:ceph:ceph-ansible:3.2.49
-
cpe:2.3:a:ceph:ceph-ansible:3.2.5
-
cpe:2.3:a:ceph:ceph-ansible:3.2.50
-
cpe:2.3:a:ceph:ceph-ansible:3.2.51
-
cpe:2.3:a:ceph:ceph-ansible:3.2.52
-
cpe:2.3:a:ceph:ceph-ansible:3.2.53
-
cpe:2.3:a:ceph:ceph-ansible:3.2.6
-
cpe:2.3:a:ceph:ceph-ansible:3.2.7
-
cpe:2.3:a:ceph:ceph-ansible:3.2.8
-
cpe:2.3:a:ceph:ceph-ansible:3.2.9
-
cpe:2.3:a:ceph:ceph-ansible:4.0.0
-
cpe:2.3:a:ceph:ceph-ansible:4.0.1
-
cpe:2.3:a:ceph:ceph-ansible:4.0.10
-
cpe:2.3:a:ceph:ceph-ansible:4.0.11
-
cpe:2.3:a:ceph:ceph-ansible:4.0.12
-
cpe:2.3:a:ceph:ceph-ansible:4.0.13
-
cpe:2.3:a:ceph:ceph-ansible:4.0.14
-
cpe:2.3:a:ceph:ceph-ansible:4.0.15
-
cpe:2.3:a:ceph:ceph-ansible:4.0.16
-
cpe:2.3:a:ceph:ceph-ansible:4.0.17
-
cpe:2.3:a:ceph:ceph-ansible:4.0.18
-
cpe:2.3:a:ceph:ceph-ansible:4.0.19
-
cpe:2.3:a:ceph:ceph-ansible:4.0.2
-
cpe:2.3:a:ceph:ceph-ansible:4.0.20
-
cpe:2.3:a:ceph:ceph-ansible:4.0.21
-
cpe:2.3:a:ceph:ceph-ansible:4.0.22
-
cpe:2.3:a:ceph:ceph-ansible:4.0.23
-
cpe:2.3:a:ceph:ceph-ansible:4.0.24
-
cpe:2.3:a:ceph:ceph-ansible:4.0.25
-
cpe:2.3:a:ceph:ceph-ansible:4.0.25.1
-
cpe:2.3:a:ceph:ceph-ansible:4.0.25.2
-
cpe:2.3:a:ceph:ceph-ansible:4.0.26
-
cpe:2.3:a:ceph:ceph-ansible:4.0.27
-
cpe:2.3:a:ceph:ceph-ansible:4.0.28
-
cpe:2.3:a:ceph:ceph-ansible:4.0.29
-
cpe:2.3:a:ceph:ceph-ansible:4.0.3
-
cpe:2.3:a:ceph:ceph-ansible:4.0.30
-
cpe:2.3:a:ceph:ceph-ansible:4.0.31
-
cpe:2.3:a:ceph:ceph-ansible:4.0.32
-
cpe:2.3:a:ceph:ceph-ansible:4.0.33
-
cpe:2.3:a:ceph:ceph-ansible:4.0.34
-
cpe:2.3:a:ceph:ceph-ansible:4.0.34.1
-
cpe:2.3:a:ceph:ceph-ansible:4.0.34.2
-
cpe:2.3:a:ceph:ceph-ansible:4.0.35
-
cpe:2.3:a:ceph:ceph-ansible:4.0.36
-
cpe:2.3:a:ceph:ceph-ansible:4.0.37
-
cpe:2.3:a:ceph:ceph-ansible:4.0.38
-
cpe:2.3:a:ceph:ceph-ansible:4.0.39
-
cpe:2.3:a:ceph:ceph-ansible:4.0.4
-
cpe:2.3:a:ceph:ceph-ansible:4.0.40
-
cpe:2.3:a:ceph:ceph-ansible:4.0.41
-
cpe:2.3:a:ceph:ceph-ansible:4.0.5
-
cpe:2.3:a:ceph:ceph-ansible:4.0.6
-
cpe:2.3:a:ceph:ceph-ansible:4.0.7
-
cpe:2.3:a:ceph:ceph-ansible:4.0.8
-
cpe:2.3:a:ceph:ceph-ansible:4.0.9
-
cpe:2.3:a:ceph:ceph-ansible:5.0.0
-
cpe:2.3:a:ceph:ceph-ansible:5.0.1
-
cpe:2.3:a:ceph:ceph-ansible:5.0.2
-
cpe:2.3:a:ceph:ceph-ansible:5.0.3