{"api_version":"1","generated_at":"2026-07-23T11:56:45+00:00","cve":"CVE-2008-2368","urls":{"html":"https://cve.report/CVE-2008-2368","api":"https://cve.report/api/cve/CVE-2008-2368.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2368","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2368"},"summary":{"title":"CVE-2008-2368","description":"Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.","state":"PUBLISHED","assigner":"redhat","published_at":"2009-01-20 16:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-255","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1021608","name":"http://securitytracker.com/id?1021608","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Red Hat Certificate Server Discloses Passwords to Local Users","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2009-0006.html","name":"https://rhn.redhat.com/errata/RHSA-2009-0006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=452000","name":"https://bugzilla.redhat.com/show_bug.cgi?id=452000","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 452000 – CVE-2008-2368 Certificate System: plain text passwords stored in debug log","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33288","name":"http://www.securityfocus.com/bid/33288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Certificate System Multiple Local Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48022","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48022","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/0145","name":"http://www.vupen.com/english/advisories/2009/0145","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2009-0007.html","name":"https://rhn.redhat.com/errata/RHSA-2009-0007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/33540","name":"http://secunia.com/advisories/33540","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Certificate Server Information Disclosure - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2368","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2368","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2368","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"certificate_system","cpe6":"7.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:58:02.256Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"33540","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33540"},{"name":"ADV-2009-0145","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/0145"},{"name":"33288","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33288"},{"name":"1021608","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1021608"},{"name":"RHSA-2009:0006","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2009-0006.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=452000"},{"name":"RHSA-2009:0007","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2009-0007.html"},{"name":"redhat-cs-debuglog-info-disclosure(48022)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48022"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-01-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"33540","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33540"},{"name":"ADV-2009-0145","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/0145"},{"name":"33288","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33288"},{"name":"1021608","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1021608"},{"name":"RHSA-2009:0006","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2009-0006.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=452000"},{"name":"RHSA-2009:0007","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2009-0007.html"},{"name":"redhat-cs-debuglog-info-disclosure(48022)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48022"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2008-2368","datePublished":"2009-01-20T16:00:00.000Z","dateReserved":"2008-05-21T00:00:00.000Z","dateUpdated":"2024-08-07T08:58:02.256Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-01-20 16:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-255","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:certificate_system:7.2:*:*:*:*:*:*:*","matchCriteriaId":"27FE079E-FB15-443C-BE2E-1D4C940BB8C0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2368","Ordinal":"1","Title":"CVE-2008-2368","CVE":"CVE-2008-2368","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2368","Ordinal":"1","NoteData":"Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.","Type":"Description","Title":"CVE-2008-2368"},{"CveYear":"2008","CveId":"2368","Ordinal":"2","NoteData":"2009-01-20","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2368","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}