Bug 1437770 (CVE-2017-2665) - CVE-2017-2665 rhscon-core: creates world readable file /etc/skyring/skyring.conf which leaks mongodb password for skyring database
Summary: CVE-2017-2665 rhscon-core: creates world readable file /etc/skyring/skyring.c...
Status: CLOSED WONTFIX
Alias: CVE-2017-2665
Product: Security Response
Classification: Other
Component: vulnerability   
(Show other bugs)
Version: unspecified
Hardware: All Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20170411,repor...
Keywords: Security
Depends On:
Blocks: 1435445
TreeView+ depends on / blocked
 
Reported: 2017-03-31 06:30 UTC by Siddharth Sharma
Modified: 2018-09-07 20:58 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-05-04 11:21:30 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Siddharth Sharma 2017-03-31 06:30:16 UTC
Description:

skyring-setup command creates random password for mongodb skyring database
but it writes password in plain text to /etc/skyring/skyring.conf file which
is owned by root but read by local user. Any local user who has access to
system running skyring service will be able to get password in plain text.

Comment 1 Siddharth Sharma 2017-03-31 06:30:28 UTC
Acknowledgments:

Name: Siddharth Sharma

Comment 3 Siddharth Sharma 2017-04-11 04:05:10 UTC
Mitigation:

~]# chmod 600 /etc/skyring/skyring.conf

Comment 4 Leonardo Taccari 2018-09-07 20:58:50 UTC
Hello folks,
I think that recently CVE-2017-2665 had CPE information added.

According the description of the CVE and this bug report it seems that
it just affect rhscon-core. Is this right?

Please let me know and I'll try to request an amend via <https://cveform.mitre.org/>.


Thank you!


Note You need to log in before you can comment on or make changes to this bug.