Vulnerability Description
Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rtslib-Fb Project | Rtslib-Fb | <= 2.1.72 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00012.html
- https://github.com/open-iscsi/rtslib-fb/pull/162Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00012.html
- https://github.com/open-iscsi/rtslib-fb/pull/162Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-14019?
CVE-2020-14019 is a vulnerability with a CVSS score of 7.8 (HIGH). Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.
How severe is CVE-2020-14019?
CVE-2020-14019 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14019?
Check the references section above for vendor advisories and patch information. Affected products include: Rtslib-Fb Project Rtslib-Fb.