Description
Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
Published: 2023-05-12
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-0202 Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.\n
Github GHSA Github GHSA GHSA-j5fj-rfh6-qj85 Planet's secret file is created with excessive permissions
History

Thu, 23 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-23T20:24:55.121Z

Reserved: 2023-05-08T13:26:03.877Z

Link: CVE-2023-32303

cve-icon Vulnrichment

Updated: 2024-08-02T15:10:24.457Z

cve-icon NVD

Status : Modified

Published: 2023-05-12T21:15:09.560

Modified: 2024-11-21T08:03:04.357

Link: CVE-2023-32303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses