Описание
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.
Ссылки
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Release Notes
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 7.10.6 (исключая)
Одно из
cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:*:*:*:*:*:*:*:*
cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:7.10.6:*:*:*:*:*:*:*
cpe:2.3:a:open-xchange:open-xchange_appsuite_backend:7.10.6:revision_39:*:*:*:*:*:*
EPSS
Процентиль: 16%
0.00053
Низкий
3.2 Low
CVSS3
3.3 Low
CVSS3
Дефекты
CWE-922
CWE-732
Связанные уязвимости
CVSS3: 3.2
github
больше 2 лет назад
Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known.
EPSS
Процентиль: 16%
0.00053
Низкий
3.2 Low
CVSS3
3.3 Low
CVSS3
Дефекты
CWE-922
CWE-732