CVE-2008-2368
Description
Red Hat Certificate System 7.2 stores passwords in cleartext in debug logs with weak permissions, allowing local users to read them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Red Hat Certificate System 7.2 stores passwords in cleartext in debug logs with weak permissions, allowing local users to read them.
Vulnerability
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files [2]. These files are created with weak permissions, making them readable by any local user on the system [2].
Exploitation
An attacker with local access to the system can read the debug log files to obtain plaintext passwords. No authentication or special privileges are required beyond the ability to read the files from the filesystem [2].
Impact
Successful exploitation leads to disclosure of plaintext passwords, which may be used to gain unauthorized access to the Certificate System or other services that share the same credentials [2].
Mitigation
No fix or workaround is disclosed in the available references. Red Hat has not published a patch or mitigation for this issue in the referenced sources.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*
- (no CPE)range: = 7.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/33540nvdVendor Advisory
- rhn.redhat.com/errata/RHSA-2009-0006.htmlnvdVendor Advisory
- securitytracker.com/idnvd
- www.securityfocus.com/bid/33288nvd
- www.vupen.com/english/advisories/2009/0145nvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/48022nvd
- rhn.redhat.com/errata/RHSA-2009-0007.htmlnvd
News mentions
0No linked articles in our index yet.