CVE-2014-0068: Medium severity red hat openshift origin node utility vulnerability
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0068?
CVE-2014-0068 is considered a medium severity vulnerability due to world writable permissions leading to potential unauthorized access.
How do I fix CVE-2014-0068?
To fix CVE-2014-0068, ensure that the permissions for /var/run/watchman.pid and /var/log/watchman.output are set to restrict access to only necessary users.
What software is affected by CVE-2014-0068?
CVE-2014-0068 affects Red Hat OpenShift Origin Node Utility and certain versions of Red Hat OpenShift.
What are the risks associated with CVE-2014-0068?
The risks associated with CVE-2014-0068 include potential unauthorized access to sensitive information or manipulation of the watchman process due to world writable files.
Is CVE-2014-0068 still a concern for current systems?
CVE-2014-0068 may still be a concern for outdated systems running affected versions of Red Hat OpenShift unless patched to restrict file permissions.