PT-2018-4044 · Crowbar · Crowbar
Thomas Biege
·
Published
2018-06-08
·
Updated
2019-10-09
·
CVE-2012-0433
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
crowbar versions prior to 2012-10-02
Description
The issue concerns the creation of files with insecure permissions by the install-chef-suse.sh script, allowing local users to access confidential data.
Recommendations
For versions prior to 2012-10-02, consider updating the install-chef-suse.sh script to create files with secure permissions to prevent unauthorized access to confidential data.
Fix
Incorrect Permission
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crowbar