RubySec

Providing security resources for the Ruby community

CVE-2014-0135 (kafo): Kafo default_values.yaml Insecure Permissions Local Information Disclosure

ADVISORIES

GEM

kafo

SEVERITY

CVSS v2: 1.9

PATCHED VERSIONS

  • ~> 0.3.17
  • >= 0.5.2

DESCRIPTION

Kafo contains a flaw that is due to the program using insecure world-readable permissions for the default_values.yaml file. This may allow a local attacker to gain access to password and other unspecified sensitive information located within the file.