Description
Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0169 | Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved. |
Github GHSA |
GHSA-cpcw-p965-wpqx | rtslib-fb weak permissions for /etc/target/saveconfig.json file |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:32:14.618Z
Reserved: 2020-06-11T00:00:00.000Z
Link: CVE-2020-14019
No data.
Status : Modified
Published: 2020-06-19T11:15:10.260
Modified: 2024-11-21T05:02:21.937
Link: CVE-2020-14019
OpenCVE Enrichment
No data.
EUVD
Github GHSA