CVE-2014-0135

Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
theforemankafo
𝑥
≤ 0.3.16
theforemankafo
0.0.1
theforemankafo
0.0.2
theforemankafo
0.0.3
theforemankafo
0.0.4
theforemankafo
0.0.5
theforemankafo
0.0.6
theforemankafo
0.0.7
theforemankafo
0.0.8
theforemankafo
0.0.9
theforemankafo
0.0.10
theforemankafo
0.0.11
theforemankafo
0.0.12
theforemankafo
0.0.13
theforemankafo
0.0.14
theforemankafo
0.0.15
theforemankafo
0.0.16
theforemankafo
0.0.17
theforemankafo
0.1.0
theforemankafo
0.2.0
theforemankafo
0.2.1
theforemankafo
0.2.2
theforemankafo
0.3.0
theforemankafo
0.3.1
theforemankafo
0.3.2
theforemankafo
0.3.3
theforemankafo
0.3.4
theforemankafo
0.3.5
theforemankafo
0.3.6
theforemankafo
0.3.7
theforemankafo
0.3.8
theforemankafo
0.3.9
theforemankafo
0.3.10
theforemankafo
0.3.11
theforemankafo
0.3.12
theforemankafo
0.3.13
theforemankafo
0.3.14
theforemankafo
0.3.15
theforemankafo
0.4.0
theforemankafo
0.5.0
theforemankafo
0.5.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration