Description
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1147 | An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file. |
Github GHSA |
GHSA-q9vw-wr57-xjv3 | Information Exposure in Heketi |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T19:50:15.558Z
Reserved: 2017-10-08T00:00:00.000Z
Link: CVE-2017-15104
No data.
Status : Modified
Published: 2017-12-18T19:29:00.247
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-15104
OpenCVE Enrichment
No data.
EUVD
Github GHSA