WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2013-12-23 23:55
Updated : 2024-02-04 18:16
NVD link : CVE-2013-3709
Mitre link : CVE-2013-3709
CVE.ORG link : CVE-2013-3709
JSON object : View
Products Affected
suse
- studio_onsite
- webyast
novell
- suse_lifecycle_management_server
CWE
CWE-264
Permissions, Privileges, and Access Controls