During an audit of file permissions within CloudForms it was found that the /etc/pulp/pulp.conf is world readable. This file can contain the following sensitive information: # default_password: default password for admin # Highly recommend changing the default_password with "pulp-admin user update" # [server] ... default_login: admin default_password: CVkiDB/JKHhHp7+PlkfaqizG ... oauth_key: katello oauth_secret: zH9ZXu6JhDwlx9GjshbFaa0Q This file should not be world readable, it should only be readable by the user/group that pulp runs as.
Acknowledgements: This issue was discovered by Kurt Seifried of the Red Hat Security Response Team.
This issue has been addressed in following products: CloudForms for RHEL 6 CloudForms Tools for RHEL 5 Via RHSA-2012:1543 https://rhn.redhat.com/errata/RHSA-2012-1543.html