PT-2019-14340 · Wtf · Wtf

Senorprogrammer

·

Publicado

2019-08-28

·

Atualizado

2020-08-24

·

CVE-2019-15716

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WTF versions prior to 0.19.0
Description The issue concerns the permissions of the config.yml file, which might be misconfigured or based on unsafe OS defaults, potentially allowing local attackers to read sensitive information such as passwords or API keys.
Recommendations For versions prior to 0.19.0, ensure the permissions of the config.yml file are properly set to prevent unauthorized access. As a temporary workaround, consider manually configuring the permissions of the config.yml file to restrict access until a fixed version is available.

Exploit

Correção

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15716

Produtos afetados

Wtf