cbcvebase.
CVE-2013-3709
published 2013-12-23

CVE-2013-3709: WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from…

PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.48%
38.3th percentile
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.

Affected

3 ranges
VendorProductVersion rangeFixed in
novellsuse_lifecycle_management_server
susestudio_onsite
susewebyast
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.