RHSA-2024:1403: Moderate: fwupd security update
Moderate: fwupd security update
Other sources
The fwupd packages provide a service that allows session software to update device firmware.Security Fix(es): fwupd: world readable password in /etc/fwupd/redfish.conf (CVE-2022-3287) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1403?
The severity of RHSA-2024:1403 is categorized as moderate.
How do I fix RHSA-2024:1403?
To resolve RHSA-2024:1403, update the fwupd package to version 1.7.8-2.el8_8 or later.
What vulnerability is addressed in RHSA-2024:1403?
RHSA-2024:1403 addresses a vulnerability where a world-readable password exists in /etc/fwupd/redfish.conf, identified as CVE-2022-3287.
Who is affected by RHSA-2024:1403?
RHSA-2024:1403 affects all users of the fwupd package on supported versions of Red Hat Enterprise Linux.
Is there any workaround for RHSA-2024:1403?
There is no specific workaround for RHSA-2024:1403; applying the security update is recommended.