PT-2017-13871 · Red Hat · Heketi

Publicado

2017-12-18

·

Atualizado

2024-06-04

·

CVE-2017-15103

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Heketi version 5
Description A security flaw was discovered in the Heketi server API, allowing an authenticated user to send specially crafted requests, potentially leading to remote command execution as the user running the Heketi server and possibly privilege escalation.
Recommendations For Heketi version 5, consider restricting access to the API until a fix is available, and avoid using the API for sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15103
GHSA-6G56-V9QG-JP92
GO-2024-2763
RHSA-2017:3481

Produtos afetados

Heketi