KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator\'s password in a file without appropriate file access controls, allowing all local users to read its content.
Metrics
CVSS Version: 3.1 |
Base Score: 2.9 LOW Vector: CVSS:3.1/AC:H/AV:L/A:N/C:L/I:N/PR:N/S:U/UI:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* NONE User Interaction (UI)* NONE Scope (S)* UNCHANGED