Pulp in Red Hat CloudForms before 1.1 logs administrative passwords in a world-readable file, which allows local users to read pulp administrative passwords by reading production.log.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/80547 | vdb entry |
http://osvdb.org/88139 | vdb entry |
http://secunia.com/advisories/51472 | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2012-1543.html | vendor advisory |
http://www.securityfocus.com/bid/56819 | vdb entry |