Impact
This vulnerability exists in openssl_encrypt versions before 1.4.9. The desktop GUI writes decrypted plaintext files with insecure default file permissions, allowing any local user on a multi‑user system to read the decrypted output. The weakness is an Insecure Permissions issue (CWE‑276) that can result in a confidentiality breach of data that was intended to remain protected after decryption.
Affected Systems
Installations of the jahlives OpenSSL Encrypt application running any version older than 1.4.9 are affected. The issue is confined to the desktop GUI component that writes decrypted files to the file system.
Risk and Exploitability
The CVSS score of 8.6 classifies the vulnerability as High severity. No EPSS score is publicly reported, and the vulnerability is not listed in the CISA KEV catalog. Attackers must have local, unprivileged access and the ability to launch the GUI; once the GUI creates a decrypted file, its world‑readable permissions permit any local user to read the file’s contents.
OpenCVE Enrichment