Skip to content

Security Onion 2 prior to 2.3.30 has incorrect permissions on /nsm/backup/

Low
dougburks published GHSA-pv78-459c-rmpm Mar 1, 2021

Package

Security Onion 2

Affected versions

< 2.3.30

Patched versions

2.3.30

Description

Impact

Security Onion 2 prior to 2.3.30 has incorrect permissions on /nsm/backup/ which allows non-root users to access backup files.

Patches

This issue has been resolved in Security Onion 2.3.30. Starting in 2.3.30, new installations will automatically have correct permissions on /nsm/backup/. Older installations running soup to update will automatically get correct permissions on /nsm/backup/.

Workarounds

Affected users who cannot immediately upgrade to 2.3.30 can manually fix the permissions on /nsm/backup/ as follows:

chmod 700 /nsm/backup

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs