Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers in a directory that is world-readable before later modifying the permissions, which might allow local users to read the generated RSA keys via reading the key files while the installation process is running.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pulp 信息泄露漏洞
Vulnerability Description
pulp_ansible是Pulp开源的一个支持托管 Role 和 Collection Ansible 内容的 Pulp 插件。 Pulp 2.8.3版本存在信息泄露漏洞。本地攻击者利用该漏洞可以读取已生成的RSA密钥。
CVSS Information
N/A
Vulnerability Type
N/A