Bug 1401661 (CVE-2016-7066) - CVE-2016-7066 admin-cli: Any local users can connect to jboss-cli
Summary: CVE-2016-7066 admin-cli: Any local users can connect to jboss-cli
Keywords:
Status: NEW
Alias: CVE-2016-7066
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=important,public=20171213,repo...
Depends On:
Blocks: 1349683 1520314
TreeView+ depends on / blocked
 
Reported: 2016-12-05 19:26 UTC by Bharti Kundal
Modified: 2019-06-08 21:38 UTC (History)
23 users (show)

Fixed In Version: eap 7.1.0
Doc Type: If docs needed, set a value
Doc Text:
It was found that the improper default permissions on /tmp/auth directory in EAP 7 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
JBoss Issue Tracker JBEAP-5177 Minor Verified Embargoed CVE-2016-7066 JBoss installers with executable permissions 2019-05-01 01:46:22 UTC
Red Hat Product Errata RHSA-2017:3456 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 22:31:03 UTC

Description Bharti Kundal 2016-12-05 19:26:24 UTC
The improper default permissions on /tmp/auth directory can allow any local user to connect to CLI and allow arbitary operations.

Comment 5 errata-xmlrpc 2017-12-13 17:34:12 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456

Comment 6 Sam Fowler 2019-05-01 04:25:43 UTC
Acknowledgments:

Name: Jeremy Choi (Red Hat)


Note You need to log in before you can comment on or make changes to this bug.