Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3891

Опубликовано: 15 апр. 2019
Источник: nvd
CVSS3: 5.5
CVSS3: 7.8
CVSS2: 2.1
EPSS Низкий

Описание

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:satellite:6.4:*:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00042
Низкий

5.5 Medium

CVSS3

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-532
CWE-532

Связанные уязвимости

CVSS3: 5.5
redhat
почти 7 лет назад

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.

CVSS3: 7.8
github
больше 3 лет назад

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.

EPSS

Процентиль: 13%
0.00042
Низкий

5.5 Medium

CVSS3

7.8 High

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-532
CWE-532