Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0164

Опубликовано: 01 мая 2014
Источник: redhat
CVSS2: 4.6

Описание

openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1mcollectiveAffected
Red Hat OpenShift Enterprise 2ruby193-mcollectiveAffected
Red Hat OpenShift Enterprise 2.0openshift-origin-broker-utilFixedRHSA-2014:046001.05.2014
RHEL 6 Version of OpenShift Enterprise 1.2openshift-origin-broker-utilFixedRHSA-2014:046101.05.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1083847mcollective: world readable client config

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.

nvd
почти 12 лет назад

openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.

debian
почти 12 лет назад

openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise ...

github
больше 3 лет назад

openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.

4.6 Medium

CVSS2