Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-532c-wf5h-wp4m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

EPSS

Процентиль: 12%
0.00041
Низкий

7 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 4.8
redhat
почти 9 лет назад

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

CVSS3: 4.8
nvd
больше 7 лет назад

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

EPSS

Процентиль: 12%
0.00041
Низкий

7 High

CVSS3

Дефекты

CWE-522