CVE-2014-0164: Low severity redhat Openshift vulnerability
openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0164?
CVE-2014-0164 is classified as a moderate severity vulnerability due to its potential for local user exploitation.
How do I fix CVE-2014-0164?
To fix CVE-2014-0164, ensure that the permissions for the mcollective client.cfg configuration file are set appropriately to restrict access.
Which versions of Red Hat OpenShift are affected by CVE-2014-0164?
CVE-2014-0164 affects Red Hat OpenShift Enterprise versions 1.2.7 and 2.0.5.
What potential impact does CVE-2014-0164 have?
CVE-2014-0164 can allow local users to read sensitive information, including credentials, from the unsecured configuration file.
Are there any known exploits for CVE-2014-0164?
As of the latest information, no public exploits specifically targeting CVE-2014-0164 have been reported.