Lucene search

K
githubGitHub Advisory DatabaseGHSA-HXVP-655X-XXQV
HistoryMay 17, 2022 - 4:44 a.m.

Kafo allows local users to obtain passwords and other sensitive information by reading default_values.yaml

2022-05-1704:44:31
GitHub Advisory Database
github.com
14

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.

Affected configurations

Vulners
Node
theforemankafoRange<0.5.2
OR
theforemankafoRange<0.3.17
CPENameOperatorVersion
kafolt0.5.2
kafolt0.3.17

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

Related for GHSA-HXVP-655X-XXQV