Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14019
HistoryJul 08, 2020 - 6:20 a.m.

CVE-2020-14019

2020-07-0806:20:41
redhat.com
access.redhat.com
9

EPSS

0

Percentile

12.6%

A flaw was found in Open-iSCSI rtslib-fb through versions 2.1.72, where it has weak permissions for /etc/target/saveconfig.json because the shutil.copyfile, instead of shutil.copy is used, and permissions are not preserved upon editing. This flaw allows an attacker with prior access to /etc/target/saveconfig.json to access a later version, resulting in a loss of integrity, depending on their permission settings. The highest threat from this vulnerability is to confidentiality.