PT-2018-8571 · Juniper Networks · Jsnapy
Published
2018-04-11
·
Updated
2019-10-09
·
CVE-2018-0023
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
JSNAPy versions prior to 1.3.0
Description:
The default configuration and sample files of the JSNAPy automation tool have insecure file and directory permissions, allowing unprivileged local users to alter files and insert unintended operations. This issue affects users who downloaded and installed JSNAPy from github.
Recommendations:
For JSNAPy versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting write access to the configuration and sample files to prevent unauthorized modifications.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsnapy