PT-2018-8571 · Juniper Networks · Jsnapy

Published

2018-04-11

·

Updated

2019-10-09

·

CVE-2018-0023

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: JSNAPy versions prior to 1.3.0
Description: The default configuration and sample files of the JSNAPy automation tool have insecure file and directory permissions, allowing unprivileged local users to alter files and insert unintended operations. This issue affects users who downloaded and installed JSNAPy from github.
Recommendations: For JSNAPy versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the configuration and sample files to prevent unauthorized modifications.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-0023
GHSA-QC55-VM3J-74GP
PYSEC-2018-84

Affected Products

Jsnapy