Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4574

Опубликовано: 04 дек. 2012
Источник: redhat
CVSS2: 4.9

Описание

Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
RHUI for RHEL 6pulpAffected
CloudForms for RHEL 6candlepinFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6goferFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6grinderFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6katelloFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6katello-agentFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6katello-certs-toolsFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6katello-cliFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6katello-cli-testsFixedRHSA-2012:154304.12.2012
CloudForms for RHEL 6katello-configureFixedRHSA-2012:154304.12.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=872487pulp /etc/pulp/pulp.conf world readable, contains default admin password

4.9 Medium

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

github
больше 3 лет назад

Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

4.9 Medium

CVSS2