PT-2018-8571 · Juniper Networks · Jsnapy

Publicado

2018-04-11

·

Atualizado

2019-10-09

·

CVE-2018-0023

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: JSNAPy versions prior to 1.3.0
Description: The default configuration and sample files of the JSNAPy automation tool have insecure file and directory permissions, allowing unprivileged local users to alter files and insert unintended operations. This issue affects users who downloaded and installed JSNAPy from github.
Recommendations: For JSNAPy versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the configuration and sample files to prevent unauthorized modifications.

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-0023
GHSA-QC55-VM3J-74GP
PYSEC-2018-84

Produtos afetados

Jsnapy