Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13867

Опубликовано: 05 июн. 2020
Источник: redhat
CVSS3: 5.5

Описание

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

An access flaw was found in targetcli, where the /etc/target and underneath backup directory/files were world-readable. This flaw allows a local attacker to access potentially sensitive information such as authentication credentials from the /etc/target/saveconfig.json and backup files. The highest threat from this vulnerability is to confidentiality.

Отчет

The version of targetcli shipped with Red Hat Ceph Storage 3 sets the world-readable permissions for /etc/target and /etc/target/backup directory that store the sensitive information, hence affected by this vulnerability.

Меры по смягчению последствий

$ chmod -R og-rwx /etc/target Future backup files will still be created with incorrect permissions, but attackers will not be able to access the target directory.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2targetcliOut of support scope
Red Hat Ceph Storage 3targetcliAffected
Red Hat Enterprise Linux 7targetcliFixedRHSA-2020:543415.12.2020
Red Hat Enterprise Linux 8targetcliFixedRHSA-2020:469704.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-276
https://bugzilla.redhat.com/show_bug.cgi?id=1848143targetcli: weak permissions for /etc/target and backup files

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

CVSS3: 5.5
nvd
больше 5 лет назад

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

CVSS3: 5.5
debian
больше 5 лет назад

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/t ...

suse-cvrf
больше 5 лет назад

Security update for targetcli-fb

suse-cvrf
больше 5 лет назад

Security update for targetcli-fb

5.5 Medium

CVSS3