Total vulnerabilities in the database
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
Software | From | Fixed in |
---|---|---|
redhat / enterprise_linux | 6.0 | 6.0.x |
scientificlinux / luci | 0.26.0 | 0.26.0.x |