Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2142

Опубликовано: 17 фев. 2016
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.

An access flaw was discovered in OpenShift; the /etc/origin/master/master-config.yaml configuration file, which could contain Active Directory credentials, was world-readable. A local user could exploit this flaw to obtain authentication credentials from the master-config.yaml file.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1311220openshift: Bind password for AD account is stored in world readable file

EPSS

Процентиль: 12%
0.0004
Низкий

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
nvd
больше 9 лет назад

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.

CVSS3: 5.5
github
больше 3 лет назад

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.

EPSS

Процентиль: 12%
0.0004
Низкий

2.1 Low

CVSS2