An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
{
"nvd_published_at": "2017-12-18T19:29:00Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-552"
],
"severity": "HIGH",
"github_reviewed_at": "2021-05-19T22:48:28Z"
}