open-iscsi/targetcli-fb

open-iscsi/targetcli-fb

Releases69
Frequency2 months 2 weeks
Last Release
Stars120
Command shell for managing Linux LIO kernel target

CVE History

CVEPublishedCVSS v3CVSS v2
5.5 MEDIUM2.1 LOW

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

7.8 HIGH7.2 HIGH

A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.