CVE-2016-3696Sensitive Information Exposure in Pulp

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 83.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

NVDpulpproject/pulp2.8.4

Also affects: Fedora 24

🔴Vulnerability Details

2
GHSA
GHSA-m563-8c32-w7fx: The pulp-qpid-ssl-cfg script in Pulp before 22022-05-14
CVEList
CVE-2016-3696: The pulp-qpid-ssl-cfg script in Pulp before 22017-06-13

📋Vendor Advisories

1
Red Hat
pulp: Leakage of CA key in pulp-qpid-ssl-cfg2016-04-20

💬Community

2
Bugzilla
CVE-2016-3704 pulp: Unsafe use of bash $RANDOM for NSS DB password and seed2016-04-25
Bugzilla
CVE-2016-3696 pulp: Leakage of CA key in pulp-qpid-ssl-cfg2016-04-20
CVE-2016-3696 — Sensitive Information Exposure in Pulp | cvebase