TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2017-2665

N/A

Beschreibung

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht7/6/2018
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

mongodb:mongodbredhat:storage_console

Schwachen (CWE)

CWE-522CWE-522

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.