Описание
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
It was found that the private CA key was created in a directory that is world-readable for a small amount of time. A local user could possibly use this flaw to gain access to the private key information in the file.
Дополнительная информация
Статус:
Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1328930pulp: Leakage of CA key in pulp-qpid-ssl-cfg
EPSS
Процентиль: 28%
0.00352
Низкий
6.5 Medium
CVSS3
1.9 Low
CVSS2
Связанные уязвимости
CVSS3: 5.5
nvd
около 9 лет назад
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
CVSS3: 5.5
github
больше 4 лет назад
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
EPSS
Процентиль: 28%
0.00352
Низкий
6.5 Medium
CVSS3
1.9 Low
CVSS2