The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
http://www.s3.eurecom.fr/cve/CVE-2014-3929.txt | third party advisory |
https://github.com/Cougar/lg/issues/5 | issue tracking third party advisory patch |
https://hackerone.com/reports/16330 | third party advisory |