Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mrg-r3f5-vhvf

Опубликовано: 28 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.7
CVSS3: 5.5

Описание

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.

EPSS

Процентиль: 5%
0.00021
Низкий

5.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 года назад

The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.

suse-cvrf
12 месяцев назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 5%
0.00021
Низкий

5.7 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-497