CVE-2013-3709

CWE-2643 documents3 sources
Severity
7.2HIGH
EPSS
0.0%
top 91.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 23
Latest updateMay 17

Description

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-vr5h-9245-q2mh: WebYaST 12022-05-17
CVEList
CVE-2013-3709: WebYaST 12013-12-23
CVE-2013-3709 (HIGH CVSS 7.2) | WebYaST 1.3 uses weak permissions f | cvebase.io