Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3287

Опубликовано: 22 сент. 2022
Источник: redhat
CVSS3: 5.5

Описание

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

A flaw was found in fwupd. When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7fwupdNot affected
Red Hat Enterprise Linux 8fwupdFixedRHSA-2023:718914.11.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportfwupdFixedRHSA-2024:110605.03.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportfwupdFixedRHSA-2024:140319.03.2024
Red Hat Enterprise Linux 9fwupdFixedRHSA-2023:248709.05.2023
Red Hat Enterprise Linux 9fwupdFixedRHSA-2023:248709.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-256
Дефект:
CWE-552
https://bugzilla.redhat.com/show_bug.cgi?id=2129904fwupd: world readable password in /etc/fwupd/redfish.conf

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

CVSS3: 6.5
nvd
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

CVSS3: 6.5
debian
почти 3 года назад

When creating an OPERATOR user account on the BMC, the redfish plugin ...

CVSS3: 6.5
redos
11 месяцев назад

Уязвимость fwupd

rocky
больше 1 года назад

Moderate: fwupd security update

5.5 Medium

CVSS3