pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-06-08T18:00:00

Updated: 2024-08-05T23:47:57.133Z

Reserved: 2016-03-10T00:00:00

Link: CVE-2016-3111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-06-08T18:29:00.357

Modified: 2023-02-13T04:50:07.630

Link: CVE-2016-3111

cve-icon Redhat

Severity : Low

Publid Date: 2016-04-13T00:00:00Z

Links: CVE-2016-3111 - Bugzilla