Information disclosure in Red Hat Storage Console Node and Red Hat Storage Console - CVE-2016-7062

 

Information disclosure in Red Hat Storage Console Node and Red Hat Storage Console - CVE-2016-7062

Published: October 21, 2016


Vulnerability identifier: #VU1034
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7062
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to access potentially sensitive information on the target system.
The weakness is due to supplying of the "rhscon-core" password in plain text as a command line parameter that allows attacker to view the password.
Successful exploitation of the vulnerabilty results in disclosure of important data on the vulnerable system.

Affected software

Red Hat Storage Console Node
Red Hat Storage Console
rhscon-agent (Red Hat package)
rhscon-ceph (Red Hat package)
rhscon-core (Red Hat package)
rhscon-ui (Red Hat package)
ceph-ansible (Red Hat package)
ceph-installer (Red Hat package)
Red Hat Ceph Storage

How to mitigate CVE-2016-7062

Update solution from the vendor's site
https://access.redhat.com/

rhscon-agent (Red Hat package) - update to 0.0.19-1.el7scon
rhscon-ceph (Red Hat package) - update to 0.0.43-1.el7scon
rhscon-core (Red Hat package) - update to 0.0.45-1.el7scon
rhscon-ui (Red Hat package) - update to 0.0.60-1.el7scon
ceph-ansible (Red Hat package) - update to 1.0.5-34.el7scon
ceph-installer (Red Hat package) - update to 1.0.15-2.el7scon
Red Hat Ceph Storage - update to 2

External References

Related Security Bulletins