CVE-2024-2905

medium

Description

A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, potentially exposing sensitive authentication data to unauthorized access.

References

https://github.com/coreos/rpm-ostree/security/advisories/GHSA-2m76-cwhg-7wv6

https://bugzilla.redhat.com/show_bug.cgi?id=2271585

https://access.redhat.com/security/cve/CVE-2024-2905

https://access.redhat.com/errata/RHSA-2024:3823

https://access.redhat.com/errata/RHSA-2024:3401

Details

Source: Mitre, NVD

Published: 2024-04-25

Updated: 2024-06-12

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.2

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: Medium