CVE-2014-0135: Low severity theforeman Kafo vulnerability
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for defaultvalues.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
Other sources
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for defaultvalues.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0135?
CVE-2014-0135 has been classified as a moderate severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2014-0135?
To fix CVE-2014-0135, upgrade Kafo to version 0.5.2 or later.
What versions of Kafo are affected by CVE-2014-0135?
CVE-2014-0135 affects Kafo versions prior to 0.3.17 and 0.4.x before 0.5.2.
What kind of information does CVE-2014-0135 expose?
CVE-2014-0135 allows local users to access passwords and other sensitive data from the world-readable `default_values.yaml` file.
Is there a workaround for CVE-2014-0135?
There is no specific workaround available for CVE-2014-0135; upgrading to a secure version is recommended.