A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade rpm-ostree-libsUpgrade rpm-ostree | Jun 17, 2024 | Apr 25, 2024 |
| Oracle_linux | — | Upgrade rpm-ostreeUpgrade rpm-ostree-libs | Jun 12, 2024 | Apr 9, 2024 |
| Redhat_linux | — | Upgrade rpm-ostree-debugsourceUpgrade rpm-ostree-libsUpgrade rpm-ostree-libs-debuginfoUpgrade rpm-ostree-debuginfoUpgrade rpm-ostree | May 29, 2024 | Apr 25, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub