openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openshift | Redhat | 1.2.7 (including) | 1.2.7 (including) |
| Openshift | Redhat | 2.0.5 (including) | 2.0.5 (including) |
| Red Hat OpenShift Enterprise 2.0 | RedHat | openshift-origin-broker-util-0:1.17.6.6-1.el6op | * |
| RHEL 6 Version of OpenShift Enterprise 1.2 | RedHat | openshift-origin-broker-util-0:1.9.16-1.el6op | * |
| Mcollective | Ubuntu | upstream | * |