2.1
CVSSv2

CVE-2016-2142

Published: 08/06/2016 Updated: 13/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 3.1

Vendor Advisories

An access flaw was discovered in OpenShift; the /etc/origin/master/master-configyaml configuration file, which could contain Active Directory credentials, was world-readable A local user could exploit this flaw to obtain authentication credentials from the master-configyaml file ...