CVE-2014-5247
EPSS 0.49%
Description
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.
How to fix CVE-2014-5247
To remediate CVE-2014-5247, upgrade the affected package to a fixed version below.
- Debian/ganeti—upgrade to 2.11.5-1 or later
Is CVE-2014-5247 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.11.5-1