Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12757
HistoryJan 15, 2019 - 9:21 a.m.

Remote Code Execution (RCE)

2019-01-1509:21:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.004 Low

EPSS

Percentile

73.6%

github.com/heketi/heketi is vulnerable to remote code execution (RCE) attacks. The library doesn’t properly validate unmarshalled structures in messages, allowing a malicious user to inject and execute arbitrary code.