PT-2018-4044 · Crowbar · Crowbar

Thomas Biege

·

Published

2018-06-08

·

Updated

2019-10-09

·

CVE-2012-0433

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions crowbar versions prior to 2012-10-02
Description The issue concerns the creation of files with insecure permissions by the install-chef-suse.sh script, allowing local users to access confidential data.
Recommendations For versions prior to 2012-10-02, consider updating the install-chef-suse.sh script to create files with secure permissions to prevent unauthorized access to confidential data.

Fix

Incorrect Permission

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0433

Affected Products

Crowbar