Vulnerabilities (CVE)

Filtered by vendor Spi-inc Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-5247 1 Spi-inc 1 Ganeti 2021-09-08 2.1 LOW N/A
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.