5.5
CVSSv3

CVE-2016-3696

Published: 13/06/2017 Updated: 13/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The pulp-qpid-ssl-cfg script in Pulp prior to 2.8.5 allows local users to obtain the CA key.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 24

pulpproject pulp

Vendor Advisories

Synopsis Important: Satellite 63 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat SatelliteRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ...
It was found that the private CA key was created in a directory that is world-readable for a small amount of time A local user could possibly use this flaw to gain access to the private key information in the file ...