Описание
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
Ссылки
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.19.0 (исключая)
cpe:2.3:a:wtfutil:wtf:*:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00046
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-276
Связанные уязвимости
CVSS3: 5.5
github
больше 3 лет назад
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
EPSS
Процентиль: 14%
0.00046
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-276