CVE-2013-4281
published 2022-10-19CVE-2013-4281: In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.19%
9.5th percentile
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | < 2.1 | 2.1 |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqgj-rgfp-3x52: In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv
ghsa_unreviewed·2022-10-19
CVE-2013-4281 [MEDIUM] CWE-276 GHSA-fqgj-rgfp-3x52: In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
GHSA
GHSA-w87g-2vqm-6m24: The default configuration of broker
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-0234 [HIGH] CWE-1188 GHSA-w87g-2vqm-6m24: The default configuration of broker
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
Red Hat
openshift-origin-broker: default password creation
vendor_redhat·2014-05-14·CVSS 7.5
CVE-2014-0234 [HIGH] CWE-798 openshift-origin-broker: default password creation
openshift-origin-broker: default password creation
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-19
Published