CVE-2008-2368
published 2009-01-20CVE-2008-2368: Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.24%
15.5th percentile
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | certificate_system | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
System: plain text passwords stored in debug log
vendor_redhat·2009-01-15·CVSS 2.1
CVE-2008-2368 [LOW] System: plain text passwords stored in debug log
System: plain text passwords stored in debug log
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.
GHSA
GHSA-hj7g-ch5r-67hc: Red Hat Certificate System 7
ghsa_unreviewed·2022-05-01
CVE-2008-2368 [LOW] GHSA-hj7g-ch5r-67hc: Red Hat Certificate System 7
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33540http://securitytracker.com/id?1021608http://www.securityfocus.com/bid/33288http://www.vupen.com/english/advisories/2009/0145https://bugzilla.redhat.com/show_bug.cgi?id=452000https://exchange.xforce.ibmcloud.com/vulnerabilities/48022https://rhn.redhat.com/errata/RHSA-2009-0006.htmlhttps://rhn.redhat.com/errata/RHSA-2009-0007.htmlhttp://secunia.com/advisories/33540http://securitytracker.com/id?1021608http://www.securityfocus.com/bid/33288http://www.vupen.com/english/advisories/2009/0145https://bugzilla.redhat.com/show_bug.cgi?id=452000https://exchange.xforce.ibmcloud.com/vulnerabilities/48022https://rhn.redhat.com/errata/RHSA-2009-0006.htmlhttps://rhn.redhat.com/errata/RHSA-2009-0007.html
2009-01-20
Published