Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

Thermostat before 2.0.0 uses world-readable permissions for the web.xml configuration file, which allows local users to obtain user credentials by reading the file.

Updated:

This container includes required additional information provided by the CVE Program for this vulnerability.