Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cvv-j545-66mj

Опубликовано: 21 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

EPSS

Процентиль: 38%
0.00163
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

CVSS3: 7.5
nvd
около 6 лет назад

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

CVSS3: 7.5
debian
около 6 лет назад

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/s ...

EPSS

Процентиль: 38%
0.00163
Низкий