CVE-2016-3112
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/pulp/consumer/consumer-cert, and authenticating as a consumer user.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- pulpproject/pulp
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2016/05/20/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2016:1501
- https://bugzilla.redhat.com/attachment.cgi?id=1146538Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1326242Issue Tracking
- https://pulp.plan.io/issues/1834Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/05/20/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2016:1501
- https://bugzilla.redhat.com/attachment.cgi?id=1146538Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1326242Issue Tracking
- https://pulp.plan.io/issues/1834Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.