Lucene search

K
osvGoogleOSV:GHSA-Q9VW-WR57-XJV3
HistoryFeb 15, 2022 - 1:57 a.m.

Information Exposure in Heketi

2022-02-1501:57:18
Google
osv.dev
3

0.001 Low

EPSS

Percentile

25.3%

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

CPENameOperatorVersion
github.com/heketi/heketilt5.0.1

0.001 Low

EPSS

Percentile

25.3%