PT-2018-8571 · Juniper Networks · Jsnapy
Publicado
2018-04-11
·
Atualizado
2019-10-09
·
CVE-2018-0023
CVSS v4.0
7.1
Alta
| Vetor | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
JSNAPy versions prior to 1.3.0
Description:
The default configuration and sample files of the JSNAPy automation tool have insecure file and directory permissions, allowing unprivileged local users to alter files and insert unintended operations. This issue affects users who downloaded and installed JSNAPy from github.
Recommendations:
For JSNAPy versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the configuration and sample files to prevent unauthorized modifications.
Correção
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jsnapy