CVE-2017-15104

HIGH

Heketi < 5.0.1 - Unauthorized Sensitive Information Exposure via World-Readable Configuration File

Title source: llm
STIX 2.1

Description

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3481
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1510149
Third Party Advisory x_refsource_confirm
https://access.redhat.com/security/cve/CVE-2017-15104
Release Notes x_refsource_confirm
https://github.com/heketi/heketi/releases/tag/v5.0.1

Scores

CVSS v3 7.8
EPSS 0.0043
EPSS Percentile 34.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200 CWE-552
Status published
Products (4)
heketi/heketi 0 - 5.0.1Go
Heketi/Heketi 5.0
heketi_project/heketi 5.0.0
redhat/enterprise_linux 7.0
Published Dec 18, 2017
Tracked Since Feb 18, 2026