CVE-2023-32303
Planet's secret file is created with excessive permissions
5.5
MEDIUM
CVSS 3.1
EPSS 0.06%
描述
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
如何修補 CVE-2023-32303
要修補 CVE-2023-32303,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.1 或更新版本
- —升級至 d71415a83119c5e89d7b80d5f940d162376ee3b7 或更新版本
CVE-2023-32303 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.0.1
- from 0, < d71415a83119c5e89d7b80d5f940d162376ee3b7 | from 0, < 2.0.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |