Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-3427

Опубликовано: 02 фев. 2014
Источник: redhat
CVSS3: 5.5

Описание

EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.

A flaw was found in JBoss Enterprise Application Platform (EAP) and EC2 Amazon Machine Image (AMI). Incorrect permissions (755) for the /var/cache/jboss-ec2-eap/ directory allow a local user to read sensitive files. This vulnerability can lead to information disclosure, specifically exposing Amazon Web Services (AWS) credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 7org.jboss.eap-jboss-eap-parentNot affected
Red Hat JBoss Enterprise Application Platform 8org.jboss.eap-jboss-eap-parentNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.eap-jboss-eap-parentNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-276

5.5 Medium

CVSS3

Связанные уязвимости

nvd
больше 12 лет назад

EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.

debian
больше 12 лет назад

EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platfor ...

github
около 4 лет назад

EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files in the directory.

5.5 Medium

CVSS3