Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0257

Опубликовано: 04 янв. 2015
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

It was discovered that a directory shared between the ovirt-engine-dwhd service and a plug-in used during the service's startup had incorrect permissions. A local user could use this flaw to access files in this directory, which could potentially contain sensitive information.

Дополнительная информация

Статус:

Low
Дефект:
CWE-522
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1189085ovirt-engine-dwh: incorrect permissions on plugin file containing passwords

EPSS

Процентиль: 13%
0.00042
Низкий

3.5 Low

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

github
больше 3 лет назад

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory.

EPSS

Процентиль: 13%
0.00042
Низкий

3.5 Low

CVSS2