CVE-2015-7945
HIGHGaneti <2.9.7-2.15.2 - Info Disclosure
Title source: llmDescription
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.
Exploits (1)
References (11)
Scores
CVSS v3
7.5
EPSS
0.1355
EPSS Percentile
94.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (30)
spi-inc/ganeti
2.10.0 (5 CPE variants)
spi-inc/ganeti
2.10.1
spi-inc/ganeti
2.10.2
spi-inc/ganeti
2.10.3
spi-inc/ganeti
2.10.4
spi-inc/ganeti
2.10.5
spi-inc/ganeti
2.10.6
spi-inc/ganeti
2.10.7
spi-inc/ganeti
2.11.0 (3 CPE variants)
spi-inc/ganeti
2.11.1
... and 20 more
Published
Aug 18, 2017
Tracked Since
Feb 18, 2026