CVE-2008-2368
Last modified
CVE-2008-2368 is a vulnerability of currently unknown severity. Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Certificate System | 7.2 |
References
- http://secunia.com/advisories/33540Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-0006.htmlVendor Advisory
- http://secunia.com/advisories/33540Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2009-0006.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2368?
How severe is CVE-2008-2368?
How do I fix CVE-2008-2368?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2362Multiple integer overflows in the Render extension in the X …
- CVE-2008-2363The PartsBatch class in Pan 0.132 and earlier does not prope…
- CVE-2008-2364The ap_proxy_http_process_response function in mod_proxy_htt…
- CVE-2008-2365Race condition in the ptrace and utrace support in the Linux…
- CVE-2008-2366Untrusted search path vulnerability in a certain Red Hat bui…
- CVE-2008-2367Red Hat Certificate System 7.2 uses world-readable permissio…
- CVE-2008-2369manzier.pxt in Red Hat Network Satellite Server before 5.1.1…9.1
- CVE-2008-2370Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, an…
- CVE-2008-2371Heap-based buffer overflow in pcre_compile.c in the Perl-Com…
- CVE-2008-2372The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows lo…
- CVE-2008-2373Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2008-2374src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs …9.8
Are you affected by CVE-2008-2368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
