client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/pulp/consumer/consumer-cert, and authenticating as a consumer user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-06-08T18:00:00

Updated: 2024-08-05T23:47:57.162Z

Reserved: 2016-03-10T00:00:00

Link: CVE-2016-3112

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-06-08T18:29:00.407

Modified: 2024-11-21T02:49:24.273

Link: CVE-2016-3112

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-04-13T00:00:00Z

Links: CVE-2016-3112 - Bugzilla