CVE-2017-15103

high

Description

A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1510147

https://access.redhat.com/security/cve/CVE-2017-15103

https://access.redhat.com/errata/RHSA-2017:3481

Details

Source: Mitre, NVD

Published: 2017-12-18

Updated: 2023-02-12

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High