Heketi CVE-2017-15103 Remote Command Injection Vulnerability
BID:106191
Info
Heketi CVE-2017-15103 Remote Command Injection Vulnerability
| Bugtraq ID: | 106191 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-15103 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 28 2017 12:00AM |
| Updated: | Dec 28 2017 12:00AM |
| Credit: | Markus Krell (NTT Security) |
| Vulnerable: |
Redhat Gluster Storage Server for On-premise 3 for RHEL 7 0 Heketi Project Heketi 5.0 |
| Not Vulnerable: |
Heketi Project Heketi 5.0.1 |
Discussion
Heketi CVE-2017-15103 Remote Command Injection Vulnerability
Heketi is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
Heketi is prone to a remote command-injection vulnerability.
An attacker may exploit this issue to inject and execute arbitrary commands within the context of the affected application; this may aid in further attacks.
References
Heketi CVE-2017-15103 Remote Command Injection Vulnerability
References:
References:
- Heketi Homepage (Heketi)
- heketi/heketi (Heketi)
- heketi/heketi (Heketi)
- Bug 1510147 (CVE-2017-15103) - CVE-2017-15103 heketi: OS command injection in h (Redhat)
- CVE-2017-15103 (Redhat)
- RHSA-2017:3481 - Security Advisory (Redhat)