Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.detack.de/en/cve-2021-33923 | third party advisory |
https://confluent.io | vendor advisory |