| Vulnerability Name: | CVE-2013-3709 (CCN-90070) | ||||||||
| Assigned: | 2013-11-19 | ||||||||
| Published: | 2013-11-19 | ||||||||
| Updated: | 2014-01-14 | ||||||||
| Summary: | WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file. | ||||||||
| CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-264 | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-3709 Source: CCN Type: SUSE WebYaST Web Site Portal:WebYaST - openSUSE Source: SUSE Type: UNKNOWN SUSE-SU-2013:1894 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1952 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1954 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1961 Source: SUSE Type: UNKNOWN SUSE-SU-2014:0022 Source: CCN Type: BID-64521 WebYaST 'config/initializers/secret_token.rb' Local Privilege Escalation Vulnerability Source: CCN Type: Novell Bugzilla Bug 851116 CVE-2013-3709: webyast: local privilege escalation via secret rails tokens execution Source: CONFIRM Type: Exploit https://bugzilla.novell.com/show_bug.cgi?id=851116 Source: XF Type: UNKNOWN webyast-cve20133709-priv-esc(90070) Source: MISC Type: UNKNOWN https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/rails_secret_deserialization.rb | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||