{"id":"CVE-2017-1000199","details":"tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.","modified":"2026-07-08T12:53:47.268294Z","published":"2017-11-17T02:29:00.957Z","related":["SUSE-SU-2017:2601-1"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3277"},{"type":"ADVISORY","url":"https://github.com/open-iscsi/tcmu-runner/issues/194"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-iscsi/tcmu-runner","events":[{"introduced":"592d68205fb01140255d4e8596c0ba8979da3ea9"},{"last_affected":"3d335660333b98cd5bdb8983a619c3b00b814b3e"}],"database_specific":{"cpe":["cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.1:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.2:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.3:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:0.9.4:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.0.5:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.0:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.1:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.2:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.1.3:*:*:*:*:*:*:*","cpe:2.3:a:tcmu-runner_project:tcmu-runner:1.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.9.1"},{"last_affected":"0.9.1"},{"introduced":"0.9.2"},{"last_affected":"0.9.2"},{"introduced":"0.9.3"},{"last_affected":"0.9.3"},{"introduced":"0.9.4"},{"last_affected":"0.9.4"},{"introduced":"1.0.5"},{"last_affected":"1.0.5"},{"introduced":"1.1.0"},{"last_affected":"1.1.0"},{"introduced":"1.1.1"},{"last_affected":"1.1.1"},{"introduced":"1.1.2"},{"last_affected":"1.1.2"},{"introduced":"1.1.3"},{"last_affected":"1.1.3"},{"introduced":"1.2.0"},{"last_affected":"1.2.0"}],"source":"CPE_STRING"}}],"versions":["0.9.1","0.9.2","0.9.3","0.9.4","1.0.5","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","v1.2.0","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0","v0.9.4","v0.9.3","v0.9.2","v0.9.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000199.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}