CVE-2017-15104
published 2017-12-18CVE-2017-15104: An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
34.7th percentile
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | heketi_heketi | >= 0 < 5.0.1+incompatible | 5.0.1+incompatible |
| github.com | heketi_heketi | >= 0 < 5.0.1 | 5.0.1 |
| heketi | heketi | — | — |
| heketi_project | heketi | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Information Exposure in Heketi in github.com/heketi/heketi
osv·2024-08-21
CVE-2017-15104 Information Exposure in Heketi in github.com/heketi/heketi
Information Exposure in Heketi in github.com/heketi/heketi
Information Exposure in Heketi in github.com/heketi/heketi
OSV
Information Exposure in Heketi
osv·2022-02-15
CVE-2017-15104 [HIGH] Information Exposure in Heketi
Information Exposure in Heketi
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
GHSA
Information Exposure in Heketi
ghsa·2022-02-15
CVE-2017-15104 [HIGH] CWE-552 Information Exposure in Heketi
Information Exposure in Heketi
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
Red Hat
heketi: Information disclosure through world readable file
vendor_redhat·2017-12-18·CVSS 7.8
CVE-2017-15104 [HIGH] CWE-552 heketi: Information disclosure through world readable file
heketi: Information disclosure through world readable file
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
An access flaw was found in heketi, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15104 heketi: Information disclosure through world readable file [fedora-all]
bugzilla·2017-12-18·CVSS 7.8
CVE-2017-15104 [HIGH] CVE-2017-15104 heketi: Information disclosure through world readable file [fedora-all]
CVE-2017-15104 heketi: Information disclosure through world readable file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2017-15104 heketi: Information disclosure through world readable file [epel-all]
bugzilla·2017-12-18·CVSS 7.8
CVE-2017-15104 [HIGH] CVE-2017-15104 heketi: Information disclosure through world readable file [epel-all]
CVE-2017-15104 heketi: Information disclosure through world readable file [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2017-15104 heketi: Information disclosure through world readable file
bugzilla·2017-11-06·CVSS 7.8
CVE-2017-15104 [HIGH] CVE-2017-15104 heketi: Information disclosure through world readable file
CVE-2017-15104 heketi: Information disclosure through world readable file
It was discovered that sensitive information could be disclosed through world readable file heketi.json containing private keys in heketi 5.x and previous.
https://access.redhat.com/security/vulnerabilities/3246991
Discussion:
Acknowledgments:
Name: Siddharth Sharma (Red Hat)
---
In reply to comment 0:
Does this also mean that the passwords are not being stored properly (hashed, or at least encrypted) as well?
---
Created heketi tracking bugs for this issue:
Affects: epel-all [bug 1527161]
Affects: fedora-all [bug 1527160]
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.3 for RHEL 7
Via RHSA-2017:3481 https://access.redhat.com/errata/RHSA-2017:3481
https://access.redhat.com/errata/RHSA-2017:3481https://access.redhat.com/security/cve/CVE-2017-15104https://bugzilla.redhat.com/show_bug.cgi?id=1510149https://github.com/heketi/heketi/releases/tag/v5.0.1https://access.redhat.com/errata/RHSA-2017:3481https://access.redhat.com/security/cve/CVE-2017-15104https://bugzilla.redhat.com/show_bug.cgi?id=1510149https://github.com/heketi/heketi/releases/tag/v5.0.1
2017-12-18
Published