Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4574

Опубликовано: 04 янв. 2013
Источник: redhat
CVSS3: 5.5

Описание

Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

A flaw was found in Pulp, as used in Red Hat CloudForms. This vulnerability allows a local user to read the administrative password due to world-readable permissions on the pulp.conf configuration file. This information disclosure could enable unauthorized access to sensitive system credentials.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-538

5.5 Medium

CVSS3

Связанные уязвимости

nvd
больше 13 лет назад

Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

github
около 4 лет назад

Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.

5.5 Medium

CVSS3