CVE-2015-7945
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 9.36% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- spi-inc/ganeti
- Source
- cve@mitre.org
References
- http://docs.ganeti.org/ganeti/2.10/html/news.html#version-2-10-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.11/html/news.html#version-2-11-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.12/html/news.html#version-2-12.6Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.13/html/news.html#version-2-13-3Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.14/html/news.html#version-2-14-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.15/html/news.html#version-2-15-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.9/html/news.html#version-2-9-7Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/135101/Ganeti-Leaked-Secret-Denial-Of-Service.htmlPatch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2016/dsa-3431
- http://www.ocert.org/advisories/ocert-2015-012.htmlPatch, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39169/
- http://docs.ganeti.org/ganeti/2.10/html/news.html#version-2-10-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.11/html/news.html#version-2-11-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.12/html/news.html#version-2-12.6Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.13/html/news.html#version-2-13-3Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.14/html/news.html#version-2-14-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.15/html/news.html#version-2-15-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.9/html/news.html#version-2-9-7Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/135101/Ganeti-Leaked-Secret-Denial-Of-Service.htmlPatch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2016/dsa-3431
- http://www.ocert.org/advisories/ocert-2015-012.htmlPatch, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39169/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.