EIQ-2019-0025
ID |
EIQ-2019-0025 |
CVE |
- |
Description |
Incorrect default permissions for the platform settings file |
Date |
13 Jun 2019 |
Severity |
2 - MEDIUM |
CVSSv3 score |
CVSSv3 score not available on NIST NVD. |
Status |
2.5.0 |
Assessment |
The packaging process that produces install packages for EclecticIQ Platform takes care of, among other things, setting default file access rights and permissions. The current access level for the the platform settings file is 644 / rw-r--r--. |
Mitigation |
To manually set these values in earlier platform releases:
|
Affected versions |
2.4.0 and earlier. |
Notes |
For more information about the weakness, see CWE-276. To successfully execute commands in the command line or in the terminal, you may require root-level access rights.
|
< Back to all security issues and mitigation actions
In release notes 2.5.0