REDHAT-BUG-451998: Medium severity red hat certificate system vulnerability
It was discovered that Red Hat Certificate System use insecure default file permissions on configuration files (such as password.conf) that may contain authentication credentials or other sensitive information that should only be accessible to administrative and service users.
This problem allows any local user to read Red Hat Certificate System configuration files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-451998?
The severity of REDHAT-BUG-451998 is considered high due to the insecure file permissions that expose sensitive information.
How do I fix REDHAT-BUG-451998?
To fix REDHAT-BUG-451998, update the file permissions on configuration files to restrict access to authorized administrative and service users only.
What files are affected by REDHAT-BUG-451998?
Files affected by REDHAT-BUG-451998 include configuration files like password.conf that may contain sensitive authentication credentials.
Who is affected by REDHAT-BUG-451998?
Administrators and service users of Red Hat Certificate System are affected by REDHAT-BUG-451998 due to the risk of unauthorized access to sensitive information.
Is there a patch for REDHAT-BUG-451998?
Yes, there are patches available for REDHAT-BUG-451998, which can be applied to secure the file permissions properly.