CVE-2020-14019

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2020
Last modified:
07/11/2023

Description

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rtslib-fb_project:rtslib-fb:*:*:*:*:*:*:*:* 2.1.72 (including)