CVE-2013-0600
published 2013-05-09CVE-2013-0600: Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and…
PriorityP351critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.72%
84.4th percentile
Unspecified vulnerability on IBM WebSphere DataPower XC10 Appliance devices 2.0 and 2.1 through 2.1 FP3 allows remote attackers to bypass authentication and perform administrative actions via unknown vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
| ibm | websphere_datapower_xc10_appliance_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4455 katello-installer: node-installer creates world readable private key file
bugzilla·2013-10-22·CVSS 2.1
CVE-2013-4455 [LOW] CVE-2013-4455 katello-installer: node-installer creates world readable private key file
CVE-2013-4455 katello-installer: node-installer creates world readable private key file
Dominic Cleal reports:
/etc/pki/tls/private/katello-node.key is created in the apache::certs class in node-installer when a child Pulp node is deployed.
It contains the private key for the node, that's normally kept in files with 0600 permissions.
Discussion:
Upstream commit:
https://github.com/Katello/node-installer/commit/15e01086bcb3f5d42525730e8b162bca11bec85e
---
Added a patch accidentally to this BZ entry, removed.
---
This was verified and delivered with Satellite 6 MDP2. Upstream has also been addressed.
---
This flaw is already been fixed:
* Actual tracker: https://bugzilla.redhat.com/show_bug.cgi?id=1021119
* Downstream patch: https://gitlab.satellite.lab.eng.rdu2.redhat.com/satell
Bugzilla
CVE-2013-1977 openstack-keystone: Insecure management of LDAP and admin_token configuration file values
bugzilla·2013-04-19·CVSS 2.1
CVE-2013-1977 [LOW] CVE-2013-1977 openstack-keystone: Insecure management of LDAP and admin_token configuration file values
CVE-2013-1977 openstack-keystone: Insecure management of LDAP and admin_token configuration file values
A security flaw was found in the way Openstack Keystone (previously) performed management of LDAP password and admin_token Keystone daemon configuration file values. A local attacker could use this flaw to obtain sensitive information.
References:
[1] https://bugs.launchpad.net/keystone/+bug/1168252
[2] http://www.openwall.com/lists/oss-security/2013/04/19/2
Relevant upstream patch (Gerrit form):
[3] https://review.openstack.org/#/c/26826/
Discussion:
Further CVE-2013-1977 vs CVE-2013-2006 ids disambiguation:
https://bugs.launchpad.net/devstack/+bug/1168252/comments/7
---
CVE-2013-1977 does not affect our installer, as it was hardened previously and has 0600 permissions, as noted
2013-05-09
Published