VulnerabilityModified
CVE-2019-15716
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
MEDIUM 5.5EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.46% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- wtfutil/wtf
- Source
- cve@mitre.org
References
- https://github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.go#L71-L72Exploit, Third Party Advisory
- https://github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0Patch, Third Party Advisory
- https://github.com/wtfutil/wtf/issues/517Third Party Advisory
- https://github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.go#L71-L72Exploit, Third Party Advisory
- https://github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0Patch, Third Party Advisory
- https://github.com/wtfutil/wtf/issues/517Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.