CVE-2019-15716

MEDIUM

wtfutil/wtf < 0.19.0 - Unprotected Credential Exposure via Insecure Config File Permissions

Title source: llm
STIX 2.1

Description

WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.

References (3)

Core 3

Scores

CVSS v3 5.5
EPSS 0.0046
EPSS Percentile 36.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-276
Status published
Products (1)
wtfutil/wtf < 0.19.0
Published Aug 28, 2019
Tracked Since Feb 18, 2026