CVE-2017-2665
published 2018-07-06CVE-2017-2665: The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is…
PriorityP429high7CVSS 3.0
AVLACHPRLUINSUCHIHAH
EPSS
0.33%
24.8th percentile
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | storage_console | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-532c-wf5h-wp4m: The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring
ghsa_unreviewed·2022-05-13
CVE-2017-2665 [HIGH] CWE-522 GHSA-532c-wf5h-wp4m: The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.
Red Hat
rhscon-core: creates world readable file /etc/skyring/skyring.conf which leaks mongodb password for skyring database
vendor_redhat·2017-04-11·CVSS 4.8
CVE-2017-2665 [MEDIUM] CWE-522 rhscon-core: creates world readable file /etc/skyring/skyring.conf which leaks mongodb password for skyring database
rhscon-core: creates world readable file /etc/skyring/skyring.conf which leaks mongodb password for skyring database
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.
Mitigation: ~]# chmod 600 /etc/skyring/skyring.conf
Package: rhscon-core (Red Hat Storage Console 2) - Will not fix
No detection rules found.
No public exploits indexed.
2018-07-06
Published