Heketi-project
2 CVEs tracked since 2017. Since Dec 2017, none of them reached CISA KEV.
Heketi-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-12 | 2 | 0 |
Products
The products that kept showing up in Heketi-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 4 most recently published vulnerabilities affecting Heketi-project.
- CVE-2020-10763An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitiv...5.5
- CVE-2019-3899It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshif...9.8
- CVE-2017-15103A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remot...8.8
- CVE-2017-15104An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heke...7.8
The record
- Peak rank
- #143 in Dec 2017
- Busiest month shown
- Dec 2017, 2 CVEs
- Months with a KEV entry
- 0 since Dec 2017
- Monthly snapshots
- 1 since 2017