Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3grh-xhcf-mgx4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

EPSS

Процентиль: 8%
0.0003
Низкий

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
redhat
больше 5 лет назад

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

CVSS3: 5.5
nvd
около 5 лет назад

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable. This flaw allows local users to obtain sensitive information by reading the log file. The highest threat from this vulnerability is to data confidentiality.

EPSS

Процентиль: 8%
0.0003
Низкий

Дефекты

CWE-532