CVE-2014-0201: Low severity redhat Rhevm-reports vulnerability
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0201?
CVE-2014-0201 has a moderate severity level due to its potential to expose sensitive information to local users.
How do I fix CVE-2014-0201?
To fix CVE-2014-0201, update the ovirt-engine-reports package to version 3.3.3 or later.
What type of information is compromised by CVE-2014-0201?
CVE-2014-0201 can lead to the exposure of sensitive configuration information stored in world-readable files.
Which versions of Red Hat are affected by CVE-2014-0201?
CVE-2014-0201 affects all versions of Red Hat Enterprise Virtualization reports package (rhevm-reports) prior to 3.3.3.
Who can exploit CVE-2014-0201?
CVE-2014-0201 can be exploited by local users who have access to the system where the affected software is installed.