Description
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
2GHSAGHSA-pv88-mwjw-4mh6: RHUI (Red Hat Update Infrastructure) 2↗2022-05-05 ▶ CVEListCVE-2013-4518: RHUI (Red Hat Update Infrastructure) 2↗2019-11-04 ▶ 📋Vendor Advisories
1Red HatRHUI: PKI entitlement certificates are world readable↗2014-08-11 ▶ 💬Community
1BugzillaCVE-2013-4518 RHUI: PKI entitlement certificates are world readable↗2013-11-05 ▶