{"api_version":"1","generated_at":"2026-07-23T09:49:00+00:00","cve":"CVE-2019-15716","urls":{"html":"https://cve.report/CVE-2019-15716","api":"https://cve.report/api/cve/CVE-2019-15716.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-15716","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-15716"},"summary":{"title":"CVE-2019-15716","description":"WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-08-28 15:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-276"],"metrics":[],"references":[{"url":"https://github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.go#L71-L72","name":"https://github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.go#L71-L72","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"wtf/config_files.go at 67658e172c9470e93e4122d6e2c90d01db12b0ac · wtfutil/wtf · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/wtfutil/wtf/issues/517","name":"https://github.com/wtfutil/wtf/issues/517","refsource":"MISC","tags":["Third Party Advisory"],"title":"Security: open call for thoughts on securing WTF's config file · Issue #517 · wtfutil/wtf · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0","name":"https://github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Comparing v0.18.0...v0.19.0 · wtfutil/wtf · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-15716","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15716","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"15716","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wtfutil","cpe5":"wtf","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"15716","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wtfutil","cpe5":"wtf","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-15716","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0","refsource":"MISC","name":"https://github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0"},{"url":"https://github.com/wtfutil/wtf/issues/517","refsource":"MISC","name":"https://github.com/wtfutil/wtf/issues/517"},{"refsource":"MISC","name":"https://github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.go#L71-L72","url":"https://github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.go#L71-L72"}]}},"nvd":{"publishedDate":"2019-08-28 15:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-276"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wtfutil:wtf:*:*:*:*:*:*:*:*","versionEndExcluding":"0.19.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"15716","Ordinal":"155275","Title":"CVE-2019-15716","CVE":"CVE-2019-15716","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"15716","Ordinal":"1","NoteData":"WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"15716","Ordinal":"2","NoteData":"2019-08-28","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"15716","Ordinal":"3","NoteData":"2019-08-28","Type":"Other","Title":"Modified"}]}}}