Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9vw-wr57-xjv3

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Information Exposure in Heketi

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

Пакеты

Наименование

github.com/heketi/heketi

go
Затронутые версииВерсия исправления

< 5.0.1

5.0.1

EPSS

Процентиль: 25%
0.00085
Низкий

7.8 High

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 5.5
redhat
около 8 лет назад

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

CVSS3: 7.8
nvd
около 8 лет назад

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

CVSS3: 7.8
debian
около 8 лет назад

An access flaw was found in Heketi 5, where the heketi.json configurat ...

EPSS

Процентиль: 25%
0.00085
Низкий

7.8 High

CVSS3

Дефекты

CWE-552