PT-2014-2452 · Varnish · Varnish

Publicado

2014-05-08

·

Atualizado

2023-02-13

·

CVE-2013-0345

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions varnish version 3.0.3
Description The issue allows local users to obtain sensitive information by reading the log files in the /var/log/varnish/ directory due to world-readable permissions.
Recommendations For varnish version 3.0.3, consider changing the permissions of the /var/log/varnish/ directory and its log files to restrict access and prevent unauthorized reading of sensitive information.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0345

Produtos afetados

Varnish