ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ceph-deploy(PyPI) | 0 | 1.5.23 | N/A |
CVSS Metrics