Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8945

Опубликовано: 29 июл. 2015
Источник: redhat
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3SecurityNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=1355733openshift-origin: Logging of private RSA keys into systemd journal

EPSS

Процентиль: 30%
0.00369
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.1
nvd
около 10 лет назад

openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.

EPSS

Процентиль: 30%
0.00369
Низкий

5.5 Medium

CVSS3

2.1 Low

CVSS2