7.8

CVE-2017-15104

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Heketi Project ≫ Heketi Version 5.0.0
Redhat ≫ Enterprise Linux Version 7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://access.redhat.com/errata/RHSA-2017:3481
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2017-15104
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1510149
Third Party Advisory
Issue Tracking
https://github.com/heketi/heketi/releases/tag/v5.0.1
Release Notes