First published: Wed Feb 12 2014(Updated: )
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Origin Node Utility | ||
Red Hat OpenShift | >=1.0<=2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0068 is considered a medium severity vulnerability due to world writable permissions leading to potential unauthorized access.
To fix CVE-2014-0068, ensure that the permissions for /var/run/watchman.pid and /var/log/watchman.output are set to restrict access to only necessary users.
CVE-2014-0068 affects Red Hat OpenShift Origin Node Utility and certain versions of Red Hat OpenShift.
The risks associated with CVE-2014-0068 include potential unauthorized access to sensitive information or manipulation of the watchman process due to world writable files.
CVE-2014-0068 may still be a concern for outdated systems running affected versions of Red Hat OpenShift unless patched to restrict file permissions.