Logo
vulnerabilityCVE-2017-2665
Name
CVE-2017-2665
Source
NVD ( link)Debian ( link)
Description
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
mongodb
False Positive

Vulnerability Ratings#


4.8
other
7
other
1.9
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
4.4.13
Not Affected
yocto
scarthgap
4.4.30
False Positive