PT-2017-8340 · Pulp · Pulp

Jeremy Cline

·

Published

2017-06-08

·

Updated

2023-02-13

·

CVE-2016-3111

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pulp version 2.8.3
Description The issue arises during the installation process of Pulp, where the pulp.spec generates RSA key pairs in a world-readable directory before modifying the permissions. This might allow local users to read the generated RSA keys by accessing the key files while the installation is in progress.
Recommendations For Pulp version 2.8.3, consider restricting access to the directory where the RSA key pairs are generated during the installation process to prevent local users from reading the keys. As a temporary workaround, monitor the installation process closely to minimize the time the key files are exposed.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2016-3111

Affected Products

Pulp