CVE-2016-6322: High severity red hat quickstart cloud installer vulnerability
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.
Other sources
Thom Carlin of Red Hat report:
The file /etc/qci/answers is created world readable and contains the root password for the deployed system.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6322?
CVE-2016-6322 is considered to have a medium severity due to the exposure of sensitive information.
How do I fix CVE-2016-6322?
To fix CVE-2016-6322, change the permissions of the /etc/qci/answers file to restrict access.
What systems are affected by CVE-2016-6322?
CVE-2016-6322 affects systems using the Red Hat QuickStart Cloud Installer.
What kind of information can be exposed by CVE-2016-6322?
CVE-2016-6322 allows local users to obtain the root password due to world-readable permissions.
Who reported CVE-2016-6322?
CVE-2016-6322 was reported by Thom Carlin of Red Hat.