PT-2017-8337 · Pulp · Pulp

Jeremy Cline

·

Published

2017-06-08

·

Updated

2023-02-12

·

CVE-2016-3107

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pulp versions prior to 2.8.3
Description The issue concerns a world-readable file containing the private key for the Node certificate, stored in the "/etc/pki/pulp/nodes/" directory. This allows local users to access sensitive data, potentially gaining access to the private key information.
Recommendations For versions prior to 2.8.3, update to version 2.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/etc/pki/pulp/nodes/" directory to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2016-3107

Affected Products

Pulp