← Vulnerability feed

Vulnerability record · CVE-2008-2367 · published 20 January 2009

CVE-2008-2367: Redhat certificate system permissions and access controls vulnerability

Redhat · Certificate System

Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files.

2.1 CVSS 2.0 Low EPSS 0.24% · top 86.0% CWE-264 · Permissions and access controls
2.1CVSS 2.0 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files.

AV:L/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2367 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2021-20179Dogtagpki incorrect authorization vulnerabilityA flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …EPSS 1.2%7.5CVE-2013-1886Redhat certificate system vulnerabilityFormat string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System …EPSS 2.2%6.5CVE-2017-7509Redhat certificate system improper input validation vulnerabilityAn input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is…EPSS 0.73%6.5CVE-2009-0588Redhat certificate system vulnerabilityagent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remot…EPSS 1.3%6.0CVE-2008-5082Redhat dogtag certificate system improper authentication vulnerabilityThe verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S…EPSS 0.78%5.8CVE-2010-3868Redhat certificate system improper authentication vulnerabilityRed Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w…EPSS 1.3%5.7CVE-2022-2393Pki-core project pki-core improper authorization vulnerabilityA flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.…EPSS 0.25%5.5CVE-2012-3367Redhat certificate system vulnerabilityRed Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2008-2367), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.