openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift | Redhat | 2.0.5 | 2.0.5 |
Openshift | Redhat | 1.2.7 | 1.2.7 |