Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4481

Опубликовано: 23 нояб. 2013
Источник: nvd
CVSS2: 1.9
EPSS Низкий

Описание

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:scientificlinux:luci:0.26.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 9%
0.00033
Низкий

1.9 Low

CVSS2

Дефекты

CWE-362

Связанные уязвимости

redhat
около 12 лет назад

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

github
больше 3 лет назад

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

EPSS

Процентиль: 9%
0.00033
Низкий

1.9 Low

CVSS2

Дефекты

CWE-362