PT-2014-6363 · Google · Ganeti

Publicado

2014-08-29

·

Atualizado

2021-09-08

·

CVE-2014-5247

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ganeti versions 2.10.0 through 2.10.6 Ganeti versions 2.11.0 through 2.11.4
Description The issue allows local users to obtain sensitive information, including SSL keys and remote API credentials, by reading a configuration backup file. This is related to the upgrade command and is due to the use of world-readable permissions for the configuration backup file by the UpgradeBeforeConfigurationChange function in lib/client/gnt cluster.py.
Recommendations For Ganeti versions 2.10.0 through 2.10.6, update to version 2.10.7 or later. For Ganeti versions 2.11.0 through 2.11.4, update to version 2.11.5 or later. As a temporary workaround, consider restricting access to the configuration backup file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5247

Produtos afetados

Ganeti