CVE-2016-6322

HIGH

Red Hat QuickStart Cloud Installer - Info Disclosure

Title source: llm
STIX 2.1

Description

Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1366413
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92668

Scores

CVSS v3 8.4
EPSS 0.0039
EPSS Percentile 31.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
redhat/quickstart_cloud_installer
Published Sep 22, 2016
Tracked Since Feb 18, 2026