ZeroHour

CVE-2017-15104

CVSS 3.1
7.8 high
EPSS
<1%p36
Published
()
Modified
Description

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

Vendors
heketi projectredhat
Products
heketi, enterprise linux
Weakness
CWE-552, CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.