Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3696

Опубликовано: 20 апр. 2016
Источник: redhat
CVSS3: 6.5
CVSS2: 1.9
EPSS Низкий

Описание

The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

It was found that the private CA key was created in a directory that is world-readable for a small amount of time. A local user could possibly use this flaw to gain access to the private key information in the file.

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1328930pulp: Leakage of CA key in pulp-qpid-ssl-cfg

EPSS

Процентиль: 28%
0.00352
Низкий

6.5 Medium

CVSS3

1.9 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
nvd
около 9 лет назад

The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

CVSS3: 5.5
github
больше 4 лет назад

The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

EPSS

Процентиль: 28%
0.00352
Низкий

6.5 Medium

CVSS3

1.9 Low

CVSS2