Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5946-mpw5-pqxx

Опубликовано: 21 фев. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 7.1

Описание

Incorrect Default Permissions in Cobbler

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.

Пакеты

Наименование

cobbler

pip
Затронутые версииВерсия исправления

< 3.3.1

3.3.1

EPSS

Процентиль: 8%
0.0003
Низкий

8.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.1
ubuntu
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.

CVSS3: 7.1
redhat
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.

CVSS3: 7.1
nvd
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.

CVSS3: 7.1
debian
почти 4 года назад

An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler ...

suse-cvrf
почти 4 года назад

Security update for cobbler

EPSS

Процентиль: 8%
0.0003
Низкий

8.6 High

CVSS4

7.1 High

CVSS3

Дефекты

CWE-276