Insecure File Permissions in Varnish Cache by Varnish Software
CVE-2013-0345

Currently unrated

Key Information:

Vendor
CVE Published:
8 May 2014

What is CVE-2013-0345?

The affected version of Varnish Cache mistakenly uses world-readable permissions for its log directory (/var/log/varnish/) and its log files. This configuration flaw allows local users with access to the system to read these log files, leading to potential exposure of sensitive information stored within. Organizations running Varnish Cache should review their file permissions to ensure sensitive data is adequately protected, implementing stricter access controls to mitigate the risk of unauthorized information disclosure.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.