An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/heketi/heketi(Go) | 0 | 5.0.1 | N/A |
CVSS Metrics