WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-12-23 15:55
Updated : 2014-01-13 20:26
NVD link : CVE-2013-3709
Mitre link : CVE-2013-3709
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
novell
- suse_lifecycle_management_server
suse
- studio_onsite
- webyast