Generated remediation guidance and an executive summary. No account required.
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/pulp/consumer/consumer-cert, and authenticating as a consumer user.
Cite this page
CVE-2016-3112. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2016-3112
Use CWE-284, Pulpproject vendor hub and Pulp product page to widen CVE-2016-3112 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-7143, CVE-2015-5263 and CVE-2016-3704 for nearby disclosures in the same product family.