2.1
CVSSv2

CVE-2014-5247

Published: 29/08/2014 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 prior to 2.10.7 and 2.11.0 prior to 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spi-inc ganeti 2.10.4

spi-inc ganeti 2.10.3

spi-inc ganeti 2.10.2

spi-inc ganeti 2.10.1

spi-inc ganeti 2.10.6

spi-inc ganeti 2.10.5

spi-inc ganeti 2.10.0

spi-inc ganeti 2.11.4

spi-inc ganeti 2.11.3

spi-inc ganeti 2.11.0

spi-inc ganeti 2.11.2

spi-inc ganeti 2.11.1