CVE-2024-22037
CVSS V2 None
CVSS V3 None
Description
The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.
Overview
- CVE ID
- CVE-2024-22037
- Assigner
- suse
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-28T09:46:07.525Z
- Last Modified Date
- 2024-11-28T12:15:16.583Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22037 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-22037 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22037 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-11-29 13:17:40 | Added to TrackCVE |