World-readable permissions on /etc/ceph/ceph.client.admin.keyring in ceph-deploy before 1.5.25 allow local users to obtain sensitive information

World-readable permissions on /etc/ceph/ceph.client.admin.keyring in ceph-deploy before 1.5.25 allow local users to obtain sensitive information

CVE-2015-4053 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file.

Learn more about our User Device Pen Test.