Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14019

Опубликовано: 19 июн. 2020
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

A flaw was found in Open-iSCSI rtslib-fb through versions 2.1.72, where it has weak permissions for /etc/target/saveconfig.json because the shutil.copyfile, instead of shutil.copy is used, and permissions are not preserved upon editing. This flaw allows an attacker with prior access to /etc/target/saveconfig.json to access a later version, resulting in a loss of integrity, depending on their permission settings. The highest threat from this vulnerability is to confidentiality.

Отчет

Red Hat Ceph Storage 2 and 3 are not affected because within the affected method, shutil.copyfile is not used. However, the affected method, save_to_file is outdated and contains a race condition. Hence, this issue has been rated as having a security impact of low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-rtslibOut of support scope
Red Hat Ceph Storage 3python-rtslibAffected
Red Hat Enterprise Linux 6python-rtslibOut of support scope
Red Hat Enterprise Linux 7python-rtslibFixedRHSA-2020:543515.12.2020
Red Hat Enterprise Linux 8python-rtslibFixedRHEA-2020:450504.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-282
https://bugzilla.redhat.com/show_bug.cgi?id=1854723python-rtslib: weak permissions for /etc/target/saveconfig.json

EPSS

Процентиль: 29%
0.00103
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 5 лет назад

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

CVSS3: 7.8
nvd
больше 5 лет назад

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

CVSS3: 7.8
debian
больше 5 лет назад

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/targ ...

suse-cvrf
больше 5 лет назад

Security update for python-rtslib-fb

suse-cvrf
больше 5 лет назад

Security update for python-rtslib-fb

EPSS

Процентиль: 29%
0.00103
Низкий

6.6 Medium

CVSS3