CVE-2019-15716
Summary
| CVE | CVE-2019-15716 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-28 15:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wtf/config_files.go at 67658e172c9470e93e4122d6e2c90d01db12b0ac · wtfutil/wtf · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Security: open call for thoughts on securing WTF's config file · Issue #517 · wtfutil/wtf · GitHub | MISC | github.com | Third Party Advisory |
| Comparing v0.18.0...v0.19.0 · wtfutil/wtf · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.