Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 30 Sep 2020 20:40:59 +0530
From: Hardik Vyas <>
Subject: CVE-2020-10763 heketi: gluster-block volume password details
 available in logs


An information-disclosure flaw was found in the way Heketi logs sensitive
This flaw allows an attacker with local access to the Heketi server, to
read potentially
sensitive information, such as gluster-block passwords.

CVE-2020-10763 has been assigned for this flaw.

Upstream PR:

Credit: Prasanna Kumar Kalever (Red Hat)


Hardik Vyas / Red Hat Product Security

BD48 C633 DE34 733A BBC3  3B72 8A14 AEBB D68B 9381 for urgent response

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.