PT-2018-5250 · Nylas · Nylas Mail
L2Dyo
·
Publicado
2018-01-03
·
Atualizado
2019-10-03
·
CVE-2017-1000485
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nylas Mail Lives version 2.2.2
Description
The issue allows local users to obtain sensitive authentication information via standard filesystem operations due to the use of 0755 permissions for $HOME/.nylas-mail.
Recommendations
For version 2.2.2, consider changing the permissions of $HOME/.nylas-mail to a more restrictive setting to prevent unauthorized access to sensitive authentication information.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nylas Mail