Описание
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
Ссылки
- Mailing ListThird Party Advisory
- Issue Tracking
- Issue Tracking
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
- Mailing ListThird Party Advisory
- Issue Tracking
- Issue Tracking
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.8.2-1 (включая)
cpe:2.3:a:pulpproject:pulp:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.00041
Низкий
7.1 High
CVSS3
3.6 Low
CVSS2
Дефекты
CWE-59
Связанные уязвимости
redhat
почти 10 лет назад
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
CVSS3: 7.1
github
больше 3 лет назад
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.
EPSS
Процентиль: 12%
0.00041
Низкий
7.1 High
CVSS3
3.6 Low
CVSS2
Дефекты
CWE-59