PT-2013-6354 · Suse · Webyast+4

Published

1970-01-01

·

Updated

2014-01-14

·

CVE-2013-3709

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WebYaST version 1.3 webyast-base-branding-default (affected versions not specified) webyast-base (affected versions not specified) webyast-base-testsuite (affected versions not specified)
Description The issue allows local users to gain privileges by exploiting weak permissions in the config/initializers/secret token.rb file, potentially leading to a breach of confidentiality, integrity, and availability of protected information. The exploitation can be carried out locally.
Recommendations For WebYaST version 1.3, consider restricting access to the config/initializers/secret token.rb file to prevent local users from reading the Rails secret token. For webyast-base-branding-default, webyast-base, and webyast-base-testsuite, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05644
BDU:2015-05645
BDU:2015-05646
CVE-2013-3709
OPENSUSE-SU-2013_1952-1
OPENSUSE-SU-2013_1954-1
OPENSUSE-SU-2013_1961-1

Affected Products

Suse
Webyast
Webyast-Base
Webyast-Base-Branding-Default
Webyast-Base-Testsuite