An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
{ "nvd_published_at": "2017-12-18T19:29:00Z", "github_reviewed_at": "2021-05-19T22:48:28Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-552" ] }