PT-2018-5250 · Nylas · Nylas Mail

L2Dyo

·

Publicado

2018-01-03

·

Atualizado

2019-10-03

·

CVE-2017-1000485

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nylas Mail Lives version 2.2.2
Description The issue allows local users to obtain sensitive authentication information via standard filesystem operations due to the use of 0755 permissions for $HOME/.nylas-mail.
Recommendations For version 2.2.2, consider changing the permissions of $HOME/.nylas-mail to a more restrictive setting to prevent unauthorized access to sensitive authentication information.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1000485

Produtos afetados

Nylas Mail