CVE-2020-14019

Published

Severity

CVSS v3:
7.8 HIGH
CVSS v2:
4.6 MEDIUM

Description

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:rtslib-fb_project:rtslib-fb:*:*:*:*:*:*:*:*n/a2.1.72 (including)*

External Links