The vendor explicitly identifies these products as affected by this CVE.
- liboath as a component of Red Hat Ceph Storage 4
- liboath as a component of Red Hat Ceph Storage 5
- oath-toolkit.src as a component of Red Hat Ceph Storage 5
- oath-toolkit.src as a component of Red Hat Openshift Container Storage 4
- Summary
- A vulnerability was found in a PAM module, the oath-toolkit. The module gained a feature that allowed placing the OTP state file, called the usersfile, in the home directory of the to-be-authenticated user. The PAM module performed unsafe file operations in the users' home directories. Since PAM stacks typically run as root, this flaw allows a malicious user to jeopardize an environment.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993
