Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14334

Опубликовано: 28 июл. 2020
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.

A flaw was found in Red Hat Satellite. An attacker could gain access to cache files further allowing access to cached credentials that could help the attacker to gain complete control of the Satellite instance. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

This flaw can be mitigated by manually changing the directory permissions to remove readable bits for the others:

chmod 0750 /run/foreman

Дополнительная информация

Статус:

Important
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=1858284foreman: unauthorized cache read on RPM-based installations through local user

EPSS

Процентиль: 31%
0.00115
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.

CVSS3: 8.8
debian
больше 5 лет назад

A flaw was found in Red Hat Satellite 6 which allows privileged attack ...

CVSS3: 8.8
github
больше 3 лет назад

A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.

CVSS3: 8.8
fstec
больше 5 лет назад

программного средства централизованного управления жизненным циклом программных продуктов Red Hat Satellite, связанная с недостатками разграничения доступа, позволяющая нарушителю получить полный контроль над приложением

EPSS

Процентиль: 31%
0.00115
Низкий

8.8 High

CVSS3

Уязвимость CVE-2020-14334