CVE-2017-15103
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 5.5%
exploitation probability
5.5%top 8% of all CVEs
observed exploitation
nono source reports it
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.
Affected products
Heketi · Heketi