CVE-2016-3107: Medium severity pulp project vulnerability
It was reported that Pulp node certificates containing private keys are stored in /etc/pki/pulp/nodes/ directory as world-readable.
Other sources
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3107?
CVE-2016-3107 has a medium severity due to its potential for unauthorized key access.
How do I fix CVE-2016-3107?
To fix CVE-2016-3107, update Pulp to version 2.8.3 or later to ensure that node certificates are no longer stored in world-readable files.
What versions of Pulp are affected by CVE-2016-3107?
CVE-2016-3107 affects Pulp versions prior to 2.8.3.
What are the potential risks of CVE-2016-3107?
The risks of CVE-2016-3107 include potential unauthorized access to sensitive private keys by local users.
What is the impact of CVE-2016-3107 on Pulp installations?
The impact of CVE-2016-3107 on Pulp installations can lead to security breaches if private keys are accessed by unauthorized entities.