When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.
Storing a password in plaintext may result in a system compromise.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fwupd | Fwupd | * | 1.8.5 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | fwupd-0:1.7.8-2.el8 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | fwupd-0:1.7.4-3.el8_6 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | fwupd-0:1.7.8-2.el8_8 | * |
Red Hat Enterprise Linux 9 | RedHat | fwupd-0:1.8.10-2.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | fwupd-0:1.8.10-2.el9 | * |
Fwupd | Ubuntu | focal | * |
Fwupd | Ubuntu | jammy | * |
Fwupd | Ubuntu | kinetic | * |
Fwupd | Ubuntu | trusty | * |
Fwupd | Ubuntu | xenial | * |