First published: Fri Nov 02 2012(Updated: )
During an audit of file permissions within CloudForms it was found that the /etc/pulp/pulp.conf is world readable. This file can contain the following sensitive information: # default_password: default password for admin # Highly recommend changing the default_password with "pulp-admin user update" # [server] ... default_login: admin default_password: CVkiDB/JKHhHp7+PlkfaqizG ... oauth_key: katello oauth_secret: zH9ZXu6JhDwlx9GjshbFaa0Q This file should not be world readable, it should only be readable by the user/group that pulp runs as.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.