CVE-2020-14019

medium
Published 2022-05-24 ยท Modified 2020-11-04
CVSS v3
โ€”
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

RHEA-2020:4505: python-rtslib bug fix and enhancement update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description python-rtslib: weak permissions for /etc/target/saveconfig.json Red Hat statement Red Hat Ceph Storage 2 and 3 are not affected because within the affected method, shutil.copyfile is not used. However, the affected method, save_to_file is outdated and contains a race condition. Hence, this issue has been rated as having a security impact of low. CVSS v3: 6.6โ€ฆ

Description

python-rtslib: weak permissions for /etc/target/saveconfig.json

Red Hat statement

Red Hat Ceph Storage 2 and 3 are not affected because within the affected method, shutil.copyfile is not used. However, the affected method, save_to_file is outdated and contains a race condition. Hence, this issue has been rated as having a security impact of low.

CVSS v3: 6.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7python-rtslib-0:2.1.74-1.el7_9RHSA-2020:54352020-12-15T00:00:00Z
Red Hat Enterprise Linux 8python-rtslib-0:2.1.73-2.el8RHEA-2020:45052020-11-04T00:00:00Z

Package state

ProductPackageState
Red Hat Ceph Storage 2python-rtslibOut of support scope
Red Hat Ceph Storage 3python-rtslibAffected
Red Hat Enterprise Linux 6python-rtslibOut of support scope

Apply commands

bash fix
Apply RHSA-2020:5435 for Red Hat Enterprise Linux 7
yum update -y python-rtslib
# or:
dnf upgrade -y python-rtslib

Affected

VendorProductVersion
redhatRed Hat Ceph Storage 3Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.1.71-3
sid Fixed 2.1.71-3
forky Fixed 2.1.71-3
bullseye Fixed 2.1.71-3
bookworm Fixed 2.1.71-3
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Package impact

EcosystemPackageVulnerableFixed
python PyPIrtslib-fb<2.1.732.1.73

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.