WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
| Software | From | Fixed in |
|---|---|---|
| suse / studio_onsite | 1.3 | 1.3.x |
| novell / suse_lifecycle_management_server | 1.3 | 1.3.x |
| suse / webyast | 1.3 | 1.3.x |