PT-2019-14340 · Wtf · Wtf
Senorprogrammer
·
Publicado
2019-08-28
·
Atualizado
2020-08-24
·
CVE-2019-15716
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WTF versions prior to 0.19.0
Description
The issue concerns the permissions of the config.yml file, which might be misconfigured or based on unsafe OS defaults, potentially allowing local attackers to read sensitive information such as passwords or API keys.
Recommendations
For versions prior to 0.19.0, ensure the permissions of the config.yml file are properly set to prevent unauthorized access. As a temporary workaround, consider manually configuring the permissions of the config.yml file to restrict access until a fixed version is available.
Exploit
Correção
Incorrect Default Permissions
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wtf