Описание
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4.2.0 only |
| esm-infra-legacy/trusty | not-affected | 4.2.0 only |
| precise | not-affected | 4.2.0 only |
| trusty | not-affected | 4.2.0 only |
| trusty/esm | not-affected | 4.2.0 only |
| upstream | needs-triage | |
| vivid | not-affected | 4.2.0 only |
Показывать по
EPSS
5 Medium
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate ...
ipa-kra-install in FreeIPA before 4.2.2 puts the CA agent certificate and private key in /etc/httpd/alias/kra-agent.pem, which is world readable.
EPSS
5 Medium
CVSS2
9.8 Critical
CVSS3