Описание
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
Ссылки
- Mailing ListThird Party Advisory
- PatchThird Party Advisory
- Mailing ListThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 15.4.45 (исключая)
cpe:2.3:a:chef:chef:*:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00395
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 8 лет назад
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
CVSS3: 7.5
debian
больше 8 лет назад
The knife bootstrap command in chef Infra client before version 15.4.4 ...
CVSS3: 7.5
github
больше 3 лет назад
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
EPSS
Процентиль: 60%
0.00395
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200