Back

HIGH

rhscon-core: creates world readable file /etc/skyring/skyring.conf which leaks mongodb password for skyring database

Published Jul 6, 2018

Description

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

Affected products

Remediation

Red Hat mitigation

~]# chmod 600 /etc/skyring/skyring.conf

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 6, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 11, 2017