Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qqr-wwjq-98v6

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

EPSS

Процентиль: 21%
0.00068
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-256
CWE-552

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

CVSS3: 5.5
redhat
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

CVSS3: 6.5
nvd
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

CVSS3: 6.5
debian
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin ...

CVSS3: 6.5
redos
11 месяцев назад

Уязвимость fwupd

EPSS

Процентиль: 21%
0.00068
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-256
CWE-552