Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3979-2hvm-67c3

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

EPSS

Процентиль: 56%
0.0034
Низкий

Связанные уязвимости

redhat
больше 13 лет назад

The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

nvd
около 13 лет назад

The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.

oracle-oval
около 12 лет назад

ELSA-2013-1121: sos security update (LOW)

oracle-oval
около 13 лет назад

ELSA-2012-0958: sos security, bug fix, and enhancement update (LOW)

fstec
около 12 лет назад

Уязвимость операционной системы CentOS, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации

EPSS

Процентиль: 56%
0.0034
Низкий