Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell WebYaST 权限许可和访问控制漏洞
Vulnerability Description
Novell WebYaST是美国Novell公司的一套基于Web的远程配置和管理工具。该工具可对已部署的软件应用程序映像或设备进行初始设置、远程管理等。 WebYaST 1.3版本中存在权限许可和访问控制漏洞,该漏洞源于程序对config/initializers/secret_token.rb文件设置弱权限。本地攻击者可通过读取该文件的Rails secret token利用该漏洞获取特权。
CVSS Information
N/A
Vulnerability Type
N/A