First published: Mon Apr 11 2016(Updated: )
It was reported that Pulp node certificates containing private keys are stored in /etc/pki/pulp/nodes/ directory as world-readable.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pulp Project | <=2.8.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3107 has a medium severity due to its potential for unauthorized key access.
To fix CVE-2016-3107, update Pulp to version 2.8.3 or later to ensure that node certificates are no longer stored in world-readable files.
CVE-2016-3107 affects Pulp versions prior to 2.8.3.
The risks of CVE-2016-3107 include potential unauthorized access to sensitive private keys by local users.
The impact of CVE-2016-3107 on Pulp installations can lead to security breaches if private keys are accessed by unauthorized entities.