PT-2014-3509 · Red Hat · Red Hat Openshift Enterprise
CVE-2014-0164
·
Publicado
2014-05-05
·
Atualizado
2023-02-13
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat OpenShift Enterprise versions 1.2.7 through 2.0.5
Description
The issue allows local users to obtain credentials and other sensitive information by reading a configuration file due to world-readable permissions. This affects the
mcollective client.cfg configuration file.Recommendations
For versions 1.2.7 and 2.0.5, consider changing the permissions of the
mcollective client.cfg configuration file to restrict access and prevent unauthorized reading of sensitive information.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Openshift Enterprise