CVE Vulnerabilities

CVE-2021-45097

Insufficiently Protected Credentials

Published: Dec 16, 2021 | Modified: Sep 28, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrators password in a file without appropriate file access controls, allowing all local users to read its content.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Knime_server Knime * 4.12.5 (including)
Knime_server Knime 4.13 (including) 4.13.4 (excluding)

Potential Mitigations

References