GHSA-q9vw-wr57-xjv3

Suggest an improvement
Source
https://github.com/advisories/GHSA-q9vw-wr57-xjv3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-q9vw-wr57-xjv3/GHSA-q9vw-wr57-xjv3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q9vw-wr57-xjv3
Aliases
Published
2022-02-15T01:57:18Z
Modified
2024-08-21T15:58:47.508931Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Information Exposure in Heketi
Details

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

Database specific
{
    "nvd_published_at": "2017-12-18T19:29:00Z",
    "github_reviewed_at": "2021-05-19T22:48:28Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-552"
    ]
}
References

Affected packages

Go / github.com/heketi/heketi

Package

Name
github.com/heketi/heketi
View open source insights on deps.dev
Purl
pkg:golang/github.com/heketi/heketi

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.1