CVE-2017-15104: Heketi Project Heketi

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

Affected products

Published 2017-12-18. Last modified 2026-06-17.