Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
Loading...
Loading...
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
May 8, 2014
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-0135
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.