Vulnerability Description
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Heketi Project | Heketi | 5.0.0 |
| Redhat | Enterprise Linux | 7.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2017:3481Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-15104Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1510149Issue TrackingThird Party Advisory
- https://github.com/heketi/heketi/releases/tag/v5.0.1Release Notes
- https://access.redhat.com/errata/RHSA-2017:3481Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-15104Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1510149Issue TrackingThird Party Advisory
- https://github.com/heketi/heketi/releases/tag/v5.0.1Release Notes
FAQ
What is CVE-2017-15104?
CVE-2017-15104 is a vulnerability with a CVSS score of 7.8 (HIGH). An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi....
How severe is CVE-2017-15104?
CVE-2017-15104 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15104?
Check the references section above for vendor advisories and patch information. Affected products include: Heketi Project Heketi, Redhat Enterprise Linux.