4.6
CVSSv2

CVE-2020-14019

Published: 19/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Open-iSCSI rtslib-fb up to and including 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rtslib-fb project rtslib-fb

Vendor Advisories

Debian Bug report logs - #972227 CVE-2020-14019 Package: src:python-rtslib-fb; Maintainer for src:python-rtslib-fb is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 14 Oct 2020 20:45:02 UTC Severity: important Tags: fixed-upstream, security, upstream ...
Synopsis Moderate: python-rtslib security update Type/Severity Security Advisory: Moderate Topic An update for python-rtslib is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Moderate: Red Hat OpenShift Container Storage 460 security, bug fix, enhancement update Type/Severity Security Advisory: Moderate Topic Updated images are now available for Red Hat OpenShift Container Storage 460 on Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ha ...
A flaw was found in Open-iSCSI rtslib-fb through versions 2172, where it has weak permissions for /etc/target/saveconfigjson because the shutilcopyfile, instead of shutilcopy is used, and permissions are not preserved upon editing This flaw allows an attacker with prior access to /etc/target/saveconfigjson to access a later version, resultin ...