CVE-2016-3111
—CVSS 3.0
5.5 medium
EPSS
<1%p32
Published
()
Modified
Description
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.
- Vendors
- pulpproject
- Products
- pulp
- Weakness
- CWE-200
- Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.