CVE
- Id
- 63656
- CVE No.
- CVE-2013-3709
- Status
- Candidate
- Description
- WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
- Phase
- Assigned (20130530)
- Votes
- None (candidate not yet proposed)
- Comments