Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0202 Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.\n
Github GHSA Github GHSA GHSA-j5fj-rfh6-qj85 Planet's secret file is created with excessive permissions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 23 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-01-23T20:24:55.121Z

Reserved: 2023-05-08T13:26:03.877Z

Link: CVE-2023-32303

cve-icon Vulnrichment

Updated: 2024-08-02T15:10:24.457Z

cve-icon NVD

Status : Modified

Published: 2023-05-12T21:15:09.560

Modified: 2024-11-21T08:03:04.357

Link: CVE-2023-32303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.