Vulnerability Description
Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | 3.1 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2016:1038Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1038Vendor Advisory
FAQ
What is CVE-2016-2142?
CVE-2016-2142 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by rea...
How severe is CVE-2016-2142?
CVE-2016-2142 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-2142?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift.