PT-2017-13871 · Red Hat · Heketi
Published
2017-12-18
·
Updated
2024-06-04
·
CVE-2017-15103
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Heketi version 5
Description
A security flaw was discovered in the Heketi server API, allowing an authenticated user to send specially crafted requests, potentially leading to remote command execution as the user running the Heketi server and possibly privilege escalation.
Recommendations
For Heketi version 5, consider restricting access to the API until a fix is available, and avoid using the API for sensitive operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Heketi