A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-12-18T19:00:00Z

Updated: 2024-08-05T19:50:15.563Z

Reserved: 2017-10-08T00:00:00

Link: CVE-2017-15103

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-12-18T19:29:00.200

Modified: 2023-02-12T23:28:30.600

Link: CVE-2017-15103

cve-icon Redhat

Severity : Important

Publid Date: 2017-12-18T00:00:00Z

Links: CVE-2017-15103 - Bugzilla