Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r98r-hmh2-hx4j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

EPSS

Процентиль: 30%
0.00109
Низкий

Дефекты

CWE-200

Связанные уязвимости

redhat
около 13 лет назад

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

nvd
почти 13 лет назад

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

EPSS

Процентиль: 30%
0.00109
Низкий

Дефекты

CWE-200