CVE-2017-15104: Infoleak
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Other sources
It was discovered that sensitive information could be disclosed through world readable file heketi.json containing private keys in heketi 5.x and previous.
https://access.redhat.com/security/vulnerabilities/3246991
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-15104?
CVE-2017-15104 is an access flaw in Heketi 5 where the heketi.json configuration file is world readable.
What is the severity of CVE-2017-15104?
CVE-2017-15104 has a severity rating of 7.8 (high).
How does CVE-2017-15104 affect Heketi?
CVE-2017-15104 allows an attacker with local access to the Heketi server to read plain-text passwords from the heketi.json file.
Which software versions are affected by CVE-2017-15104?
Heketi version 5.0.0 and Redhat Enterprise Linux 7.0 are affected by CVE-2017-15104.
How can I fix CVE-2017-15104?
To fix CVE-2017-15104, you should ensure that the heketi.json configuration file is not world readable.