Pulp in Red Hat CloudForms before 1.1 uses world-readable permissions for pulp.conf, which allows local users to read the administrative password by reading this file.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/80548 | vdb entry |
http://osvdb.org/88138 | vdb entry |
http://secunia.com/advisories/51472 | third party advisory vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=872487 | |
http://rhn.redhat.com/errata/RHSA-2012-1543.html | vendor advisory |
http://www.securityfocus.com/bid/56819 | vdb entry |