First published: Wed Jun 18 2008(Updated: )
It was discovered that Red Hat Certificate System may store plain text passwords in multiple debug log files (such as UserDirEnrollment password or RA wizard installer log). This problem allows any local user to extract plain text passwords from the Red Hat Certificate System debug log files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Certificate System | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2368 has a high severity due to the potential exposure of plain text passwords stored in debug log files.
To fix CVE-2008-2368, users should upgrade to a patched version of Red Hat Certificate System that eliminates plain text password logging.
CVE-2008-2368 is caused by Red Hat Certificate System storing sensitive passwords in debug logs without proper encryption.
Any local user with access to the debug log files of Red Hat Certificate System 7.2 is potentially affected by CVE-2008-2368.
The risks associated with CVE-2008-2368 include unauthorized access to sensitive information, such as user credentials, by local users.