CVE-2023-32303
Summary
| CVE | CVE-2023-32303 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-12 21:15:00 UTC |
| Updated | 2023-05-15 12:54:00 UTC |
| Description | Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand. |
Risk And Classification
Problem Types: CWE-732
There are no known software configurations currently associated with this CVE in NVD or the CVE Program record.
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 2.0.1 · planetlabs/planet-client-python · GitHub | MISC | github.com | |
| secret file is created with excessive permissions · Advisory · planetlabs/planet-client-python · GitHub | MISC | github.com | |
| enforce restricting secret file permissions to user read/write · planetlabs/planet-client-python@d71415a · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.