CVE-2020-10237: Information Exposure
(updated )
An issue was discovered in Froxlor. The installer wrote configuration parameters including passwords into files in /tmp
, setting proper permissions only after writing the sensitive data. A local attacker could have disclosed the information if he read the file at the right time, the flaw exists in _createUserdataConf
of the install/lib/class.FroxlorInstall.php
file.
References
Detect and mitigate CVE-2020-10237 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →