The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.
References
Link | Resource |
---|---|
https://www.suse.com/security/cve/CVE-2012-0433/ | Vendor Advisory |
https://bugzilla.suse.com/show_bug.cgi?id=783195 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2018-06-08 10:29
Updated : 2019-10-09 16:04
NVD link : CVE-2012-0433
Mitre link : CVE-2012-0433
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
crowbar_project
- crowbar