CVE-2012-5658

low
Published 2013-02-24 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0220.html

Application impact

VendorProductVersionsFixed
redhatopenshift{"endIncluding":"1.0"}
redhatopenshift_origin1.0.5

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.