First published: Mon Nov 06 2017(Updated: )
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Heketi Project Heketi | =5.0.0 | |
Redhat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15104 is an access flaw in Heketi 5 where the heketi.json configuration file is world readable.
CVE-2017-15104 has a severity rating of 7.8 (high).
CVE-2017-15104 allows an attacker with local access to the Heketi server to read plain-text passwords from the heketi.json file.
Heketi version 5.0.0 and Redhat Enterprise Linux 7.0 are affected by CVE-2017-15104.
To fix CVE-2017-15104, you should ensure that the heketi.json configuration file is not world readable.