PT-2014-6363 · Google · Ganeti
Publicado
2014-08-29
·
Atualizado
2021-09-08
·
CVE-2014-5247
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ganeti versions 2.10.0 through 2.10.6
Ganeti versions 2.11.0 through 2.11.4
Description
The issue allows local users to obtain sensitive information, including SSL keys and remote API credentials, by reading a configuration backup file. This is related to the upgrade command and is due to the use of world-readable permissions for the configuration backup file by the UpgradeBeforeConfigurationChange function in lib/client/gnt cluster.py.
Recommendations
For Ganeti versions 2.10.0 through 2.10.6, update to version 2.10.7 or later.
For Ganeti versions 2.11.0 through 2.11.4, update to version 2.11.5 or later.
As a temporary workaround, consider restricting access to the configuration backup file to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ganeti