KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when...
Moderate severity
Unreviewed
Published
Dec 17, 2021
to the GitHub Advisory Database
•
Updated Oct 7, 2023
Description
Published by the National Vulnerability Database
Dec 16, 2021
Published to the GitHub Advisory Database
Dec 17, 2021
Last updated
Oct 7, 2023
KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's password in a file without appropriate file access controls, allowing all local users to read its content.
References