Skip to content

CVE-2014-0135

Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0010 (0.1%)
Percentile: 27.1%
EPSS: 2026-05-06

Affects

theforeman:kafo

Technical description

Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.

Published: 5/8/2014, 2:29:13 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam