The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://docs.pulpproject.org/user-guide/release-notes/2.8.x.html#pulp-2-8-5 | permissions required |
https://access.redhat.com/errata/RHSA-2018:0336 | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1328930 | issue tracking |
https://pulp.plan.io/issues/1854 | vendor advisory issue tracking |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YM2LCC7QBRCK4LTN5EZT5OHTVAR3MYTY/ | vendor advisory |