Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-32303
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Planet's secret file is created with excessive permissions
Source: NVD (National Vulnerability Database)
Vulnerability Description
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键资源的不正确权限授予
Source: NVD (National Vulnerability Database)
Vulnerability Title
Planet SDK for Python 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Planet SDK for Python是Planet Labs开源的一个应用程序。提供了一个 Python-API 和一个命令行界面(CLI)来使用 Planet API。 Planet SDK for Python 2.0.1之前版本存在安全漏洞,该漏洞源于允许非授权用户读取用户的Planet API认证信息文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
planetlabsplanet-client-python < 2.0.1 -
II. Public POCs for CVE-2023-32303
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-32303
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-32303

No comments yet


Leave a comment