Severity
5.5MEDIUM
EPSS
0.0%
top 90.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19

Description

In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5red_hat_openshiftRed Hat Openshift 1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fqgj-rgfp-3x52: In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv2022-10-19
CVEList
CVE-2013-4281: In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv2022-10-19

📋Vendor Advisories

1
Red Hat
openshift-origin-broker: default password creation2014-05-14