REDHAT-BUG-1322706: Low severity Pulp Pulp vulnerability
It was found that newly generated CA keys by running pulp-gen-ca-certificate (which is run by spec file when pulp is installed) script are insufficiently protected against reading by other users for the time the script runs.
Vulnerable code:
https://github.com/pulp/pulp/blob/2.8.0/server/bin/pulp-gen-ca-certificate
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1322706?
REDHAT-BUG-1322706 is considered a medium severity vulnerability due to insufficient protection of CA keys.
How do I fix REDHAT-BUG-1322706?
To fix REDHAT-BUG-1322706, ensure that the CA keys generated by the pulp-gen-ca-certificate script have appropriate permissions set during the script execution.
What software is affected by REDHAT-BUG-1322706?
REDHAT-BUG-1322706 affects Pulp version 2.8.0.
What are the risks of not addressing REDHAT-BUG-1322706?
Not addressing REDHAT-BUG-1322706 can lead to unauthorized access to sensitive CA keys by other users.
How does REDHAT-BUG-1322706 impact security?
REDHAT-BUG-1322706 impacts security by exposing newly generated CA keys to potential interception or misuse by unauthorized users.