docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.10/html/news.html CVE-2015-7945
HIGH
Ganeti - Multiple Vulnerabilities
Record summary
CVE-2015-7945 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGaneti - Multiple VulnerabilitiesExploitDB exploitby Pierre KimNot analyzed1 file
References
12docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.11/html/news.html docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.12/html/news.html docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.13/html/news.html docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.14/html/news.html docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.15/html/news.html docs.ganeti.orgConfirmation
http://docs.ganeti.org/ganeti/2.9/html/news.html packetstormsecurity.com
http://packetstormsecurity.com/files/135101/Ganeti-Leaked-Secret-Denial-Of-Service.html DSA-3431Vendor advisory
http://www.debian.org/security/2016/dsa-3431 ocert.org
http://www.ocert.org/advisories/ocert-2015-012.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-7945 39169exploit
https://www.exploit-db.com/exploits/39169