Описание
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | mcollective | Affected | ||
| Red Hat OpenShift Enterprise 2 | ruby193-mcollective | Affected | ||
| Red Hat OpenShift Enterprise 2.0 | openshift-origin-broker-util | Fixed | RHSA-2014:0460 | 01.05.2014 |
| RHEL 6 Version of OpenShift Enterprise 1.2 | openshift-origin-broker-util | Fixed | RHSA-2014:0461 | 01.05.2014 |
Показывать по
Дополнительная информация
Статус:
4.6 Medium
CVSS2
Связанные уязвимости
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise ...
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
4.6 Medium
CVSS2