Information Disclosure Vulnerability in IBM Cloud Private
CVE-2018-1841
6.2MEDIUM
What is CVE-2018-1841?
IBM Cloud Private version 2.1.0 contains an information disclosure vulnerability that could allow a local user to access the Certificate Authority (CA) Private Key. This vulnerability occurs due to the CA Private Key being set to world-readable permissions in the boot/master node, enabling unauthorized access to sensitive cryptographic material. Protecting the CA Private Key is crucial as it is integral to authentication and confidentiality within the cloud environment.
Affected Version(s)
Cloud Private 2.1.0