CVE Vulnerabilities

CVE-2014-5247

Published: Aug 29, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.

Affected Software

Name Vendor Start Version End Version
Ganeti Spi-inc 2.10.0 (including) 2.10.0 (including)
Ganeti Spi-inc 2.10.0-beta1 (including) 2.10.0-beta1 (including)
Ganeti Spi-inc 2.10.0-rc1 (including) 2.10.0-rc1 (including)
Ganeti Spi-inc 2.10.0-rc2 (including) 2.10.0-rc2 (including)
Ganeti Spi-inc 2.10.0-rc3 (including) 2.10.0-rc3 (including)
Ganeti Spi-inc 2.10.1 (including) 2.10.1 (including)
Ganeti Spi-inc 2.10.2 (including) 2.10.2 (including)
Ganeti Spi-inc 2.10.3 (including) 2.10.3 (including)
Ganeti Spi-inc 2.10.4 (including) 2.10.4 (including)
Ganeti Spi-inc 2.10.5 (including) 2.10.5 (including)
Ganeti Spi-inc 2.10.6 (including) 2.10.6 (including)
Ganeti Spi-inc 2.11.0 (including) 2.11.0 (including)
Ganeti Spi-inc 2.11.0-beta1 (including) 2.11.0-beta1 (including)
Ganeti Spi-inc 2.11.0-rc1 (including) 2.11.0-rc1 (including)
Ganeti Spi-inc 2.11.1 (including) 2.11.1 (including)
Ganeti Spi-inc 2.11.2 (including) 2.11.2 (including)
Ganeti Spi-inc 2.11.3 (including) 2.11.3 (including)
Ganeti Spi-inc 2.11.4 (including) 2.11.4 (including)
Ganeti Ubuntu lucid *
Ganeti Ubuntu precise *
Ganeti Ubuntu trusty *
Ganeti Ubuntu upstream *
Ganeti Ubuntu utopic *
Ganeti Ubuntu vivid *
Ganeti Ubuntu wily *

References