Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4481

Опубликовано: 20 нояб. 2013
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

A flaw was found in the way luci generated its configuration file. The file was created as world readable for a short period of time, allowing a local user to gain access to the authentication secrets stored in the configuration file.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=988998luci: short exposure of authentication secrets while generating configuration file

EPSS

Процентиль: 9%
0.00033
Низкий

1.9 Low

CVSS2

Связанные уязвимости

nvd
около 12 лет назад

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

github
больше 3 лет назад

Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."

EPSS

Процентиль: 9%
0.00033
Низкий

1.9 Low

CVSS2