Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

L2Dyo

#32038of 53,622
7.8Total CVSS
Vulnerabilities · 1
PT-2018-5250
7.8
2018-01-03
Nylas · Nylas Mail · CVE-2017-1000485
**Name of the Vulnerable Software and Affected Versions** Nylas Mail Lives version 2.2.2 **Description** The issue allows local users to obtain sensitive authentication information via standard filesystem operations due to the use of 0755 permissions for $HOME/.nylas-mail. **Recommendations** For version 2.2.2, consider changing the permissions of $HOME/.nylas-mail to a more restrictive setting to prevent unauthorized access to sensitive authentication information.