An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
| Software | From | Fixed in |
|---|---|---|
| heketi_project / heketi | 5.0.0 | 5.0.0.x |
| redhat / enterprise_linux | 7.0 | 7.0.x |
github.com/heketi/heketi
|
- | 5.0.1 |