Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).
Metrics
Affected Vendors & Products
References
History
Tue, 07 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedorarepository
Fedorarepository fcrepo |
|
| CPEs | cpe:2.3:a:fedorarepository:fcrepo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fedorarepository
Fedorarepository fcrepo |
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23). | |
| Title | Fedora Repository fedoraIntCallUser default credentials | |
| Weaknesses | CWE-1392 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-01-23T20:25:00.614Z
Updated: 2025-02-12T20:41:30.107Z
Reserved: 2025-01-09T16:12:49.111Z
Link: CVE-2025-23012
Updated: 2025-02-12T20:35:55.317Z
Status : Analyzed
Published: 2025-01-23T21:15:15.173
Modified: 2025-10-07T16:47:21.827
Link: CVE-2025-23012
No data.