heketi project
Cloud & SaaSoss-project
Top products
Latest CVEs
The 4 most recently published vulnerabilities affecting heketi project.
- CVE-2020-10763An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitiv...5.5
- CVE-2019-3899It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshif...9.8
- CVE-2017-15104An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heke...7.8
- CVE-2017-15103A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remot...8.8