Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2665

Опубликовано: 11 апр. 2017
Источник: redhat
CVSS3: 4.8

Описание

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

Меры по смягчению последствий

~]# chmod 600 /etc/skyring/skyring.conf

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Storage Console 2rhscon-coreWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1437770rhscon-core: creates world readable file /etc/skyring/skyring.conf which leaks mongodb password for skyring database

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
nvd
больше 7 лет назад

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

CVSS3: 7
github
больше 3 лет назад

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

4.8 Medium

CVSS3