Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user's home directory, which allows local users to obtain Pandora credentials by reading this file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Kevinmehall Pithos PreferencesPithosDialog.py证书信息泄露漏洞
Vulnerability Description
Pithos 0.3.7版本当中的PreferencesPithosDialog.py没有正确限制对配置文件"~/.config/pithos.ini"的读访问。该漏洞以明文方式为Pandora.com web站点存储证书,本地用户可以通过阅读该文件获取Pandora证书。
CVSS Information
N/A
Vulnerability Type
N/A