open-iscsi/rtslib-fb

open-iscsi/rtslib-fb

Python library for configuring the Linux kernel-based multiprotocol SCSI target (LIO)

CVE History

CVEPublishedCVSS v2CVSS v3
CVE-2020-140197.8 HIGH4.6 MEDIUM
Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.