VulnerabilityModified
CVE-2017-15104
An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
HIGH 7.8EPSS 0.43%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-552, CWE-200
- Affected
- heketi project/heketi · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2017:3481Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-15104Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1510149Issue Tracking, Third Party Advisory
- https://github.com/heketi/heketi/releases/tag/v5.0.1Release Notes
- https://access.redhat.com/errata/RHSA-2017:3481Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-15104Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1510149Issue Tracking, Third Party Advisory
- https://github.com/heketi/heketi/releases/tag/v5.0.1Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.