Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0346

Опубликовано: 22 фев. 2013
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

Отчет

Red Hat does not regard this to be a security flaw. The tomcat log directory does not contain any sensitive information, and when sensitive information has been written to log files, this has been considered a security flaw in tomcat (e.g. CVE-2011-2204). This issue was reported to the Apache Tomcat project, and they have not considered it a flaw in any published security advisories.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=924841tomcat: World-readable log directory

EPSS

Процентиль: 70%
0.00636
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

nvd
больше 11 лет назад

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

debian
больше 11 лет назад

Apache Tomcat 7.x uses world-readable permissions for the log director ...

github
больше 3 лет назад

** DISPUTED ** Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

EPSS

Процентиль: 70%
0.00636
Низкий

2.1 Low

CVSS2