漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch
Vulnerability Description
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leaving git credentials readable by any local user who can traverse the dokku home directory. This vulnerability is fixed in 0.38.2.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
Dokku 信任管理问题漏洞
Vulnerability Description
Dokku Dokku是Dokku团队的一个云平台部署工具。 Dokku 0.38.2之前版本存在信任管理问题漏洞,该漏洞源于git:auth命令创建$DOKKU_ROOT/.netrc时使用默认umask 0644,导致git凭据可被本地用户读取。
CVSS Information
N/A
Vulnerability Type
N/A