Medium severity5.5NVD Advisory· Published Aug 28, 2019· Updated Jun 17, 2026
CVE-2019-15716
CVE-2019-15716
Description
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WTF/WTFdescription
Patches
Vulnerability mechanics
References
3- github.com/wtfutil/wtf/compare/v0.18.0...v0.19.0nvdPatchThird Party Advisory
- github.com/wtfutil/wtf/blob/67658e172c9470e93e4122d6e2c90d01db12b0ac/cfg/config_files.gonvdExploitThird Party Advisory
- github.com/wtfutil/wtf/issues/517nvdThird Party Advisory
News mentions
0No linked articles in our index yet.