CVE-2016-3107

The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pulpproject:pulp:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:18

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-3107', 'name': 'https://access.redhat.com/security/cve/CVE-2016-3107', 'tags': [], 'refsource': 'MISC'}
Summary It was found that the private key for the node certificate was contained in a world-readable file. A local user could possibly use this flaw to gain access to the private key information in the file. The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data.

02 Feb 2023, 14:16

Type Values Removed Values Added
Summary The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data. It was found that the private key for the node certificate was contained in a world-readable file. A local user could possibly use this flaw to gain access to the private key information in the file.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-3107 -

Information

Published : 2017-06-08 18:29

Updated : 2023-12-10 12:15


NVD link : CVE-2016-3107

Mitre link : CVE-2016-3107

CVE.ORG link : CVE-2016-3107


JSON object : View

Products Affected

pulpproject

  • pulp
CWE
CWE-284

Improper Access Control