Common Weakness Enumeration

CWE-552

Allowed

Files or Directories Accessible to External Parties

Abstraction: Base · Status: Draft

The product makes files or directories accessible to unauthorized actors, even though they should not be.

730 vulnerabilities reference this CWE, most recent first.

GHSA-6CR4-CCF3-X7H4

Vulnerability from github – Published: 2026-09-22 20:35 – Updated: 2026-09-22 20:35
VLAI
Summary
MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials
Details

Summary

Missing path validation in confluence_upload_attachment allows any authenticated MCP client to read arbitrary files from the server filesystem and exfiltrate their contents to Confluence. On Linux deployments, /proc/self/environ yields all runtime secrets in a single call.


Details

AttachmentsMixin.upload_attachment() in src/mcp_atlassian/confluence/attachments.py opens the caller-supplied file_path with no boundary check:

# line 477
files = {"file": (filename, open(file_path, "rb"))}

The download path was correctly hardened in GHSA-xjgw-4wvw-rgm4 via validate_safe_path() (lines 223, 272). That fix was not applied to the upload path, leaving it completely unguarded. The MCP tool layer (servers/confluence.py:1295) passes file_path verbatim with no additional sanitization.


PoC

# 1. Prepare target file (macOS demo; on Linux use /proc/self/environ directly)
cp ~/.aws/credentials /tmp/diagram.png

# 2. Call the MCP tool
confluence_upload_attachment(
    content_id = "<any page attacker can edit>",
    file_path  = "/tmp/diagram.png"
)

# 3. Download attachment from Confluence — contains raw credentials

Tested on mcp-atlassian 0.21.1 against live Confluence Cloud. Attachment confirmed uploaded and retrieved with full credential content intact.


Impact

Any MCP client with edit access to one Confluence page can read arbitrary files from the server process. On shared/Docker deployments, /proc/self/environ exposes all users' API tokens in a single request. Exfiltrated Atlassian tokens provide persistent API access independent of MCP, surviving server shutdown or patching.

Incomplete fix of GHSA-xjgw-4wvw-rgm4 — arbitrary file read on upload mirrors the arbitrary file write on download fixed in that advisory.


Suggested Fix

# src/mcp_atlassian/confluence/attachments.py — upload_attachment()
# Add after abspath conversion, before open():

try:
    validate_safe_path(file_path)
except ValueError as e:
    return {"success": False, "error": str(e)}

Same fix required in upload_attachments() and src/mcp_atlassian/jira/attachments.py.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "mcp-atlassian"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.22.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-77259"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-22",
      "CWE-552"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-22T20:35:16Z",
    "nvd_published_at": null,
    "severity": "HIGH"
  },
  "details": "### Summary\n\nMissing path validation in `confluence_upload_attachment` allows any authenticated MCP client to read arbitrary files from the server filesystem and exfiltrate their contents to Confluence. On Linux deployments, `/proc/self/environ` yields all runtime secrets in a single call.\n\n---\n### Details\n\n`AttachmentsMixin.upload_attachment()` in `src/mcp_atlassian/confluence/attachments.py` opens the caller-supplied `file_path` with no boundary check:\n\n```python\n# line 477\nfiles = {\"file\": (filename, open(file_path, \"rb\"))}\n```\nThe download path was correctly hardened in GHSA-xjgw-4wvw-rgm4 via `validate_safe_path()` (lines 223, 272). That fix was not applied to the upload path, leaving it completely unguarded. The MCP tool layer (`servers/confluence.py:1295`) passes `file_path` verbatim with no additional sanitization.\n\n---\n### PoC\n\n```bash\n# 1. Prepare target file (macOS demo; on Linux use /proc/self/environ directly)\ncp ~/.aws/credentials /tmp/diagram.png\n\n# 2. Call the MCP tool\nconfluence_upload_attachment(\n    content_id = \"\u003cany page attacker can edit\u003e\",\n    file_path  = \"/tmp/diagram.png\"\n)\n\n# 3. Download attachment from Confluence \u2014 contains raw credentials\n```\nTested on mcp-atlassian 0.21.1 against live Confluence Cloud. Attachment confirmed uploaded and retrieved with full credential content intact.\n\n---\n### Impact\nAny MCP client with edit access to one Confluence page can read arbitrary files from the server process. On shared/Docker deployments, `/proc/self/environ` exposes all users\u0027 API tokens in a single request. Exfiltrated Atlassian tokens provide persistent API access independent of MCP, surviving server shutdown or patching.\n\nIncomplete fix of GHSA-xjgw-4wvw-rgm4 \u2014 arbitrary file read on upload mirrors the arbitrary file write on download fixed in that advisory.\n\n\n---\n### Suggested Fix\n\n```python\n# src/mcp_atlassian/confluence/attachments.py \u2014 upload_attachment()\n# Add after abspath conversion, before open():\n\ntry:\n    validate_safe_path(file_path)\nexcept ValueError as e:\n    return {\"success\": False, \"error\": str(e)}\n```\n\nSame fix required in `upload_attachments()` and `src/mcp_atlassian/jira/attachments.py`.",
  "id": "GHSA-6cr4-ccf3-x7h4",
  "modified": "2026-09-22T20:35:16Z",
  "published": "2026-09-22T20:35:16Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-6cr4-ccf3-x7h4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sooperset/mcp-atlassian/pull/1448"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/sooperset/mcp-atlassian"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "MCP Atlassian: Arbitrary file read via confluence_upload_attachment allows exfiltration of server credentials"
}

GHSA-6HFV-JW53-QRC2

Vulnerability from github – Published: 2023-02-27 18:32 – Updated: 2023-03-04 06:30
VLAI
Details

The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-0331"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-02-27T16:15:00Z",
    "severity": "HIGH"
  },
  "details": "The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.",
  "id": "GHSA-6hfv-jw53-qrc2",
  "modified": "2023-03-04T06:30:22Z",
  "published": "2023-02-27T18:32:09Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0331"
    },
    {
      "type": "WEB",
      "url": "https://wpscan.com/vulnerability/1b4dbaf3-1364-4103-9a7b-b5a1355c685b"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6HW8-GQ2C-479X

Vulnerability from github – Published: 2022-05-24 19:10 – Updated: 2022-05-24 19:10
VLAI
Details

Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2021-36276"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2021-08-09T21:15:00Z",
    "severity": "HIGH"
  },
  "details": "Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.",
  "id": "GHSA-6hw8-gq2c-479x",
  "modified": "2022-05-24T19:10:24Z",
  "published": "2022-05-24T19:10:24Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36276"
    },
    {
      "type": "WEB",
      "url": "https://www.dell.com/support/kbdoc/en-us/000190105/dsa-2021-152-dell-client-platform-security-update-for-an-insufficient-access-control-vulnerability-in-the-dell-dbutildrv2-sys-driver"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6J5R-8VHM-P3X4

Vulnerability from github – Published: 2022-10-17 19:00 – Updated: 2022-10-21 19:01
VLAI
Details

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-2834"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-200",
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2022-10-17T12:15:00Z",
    "severity": "MODERATE"
  },
  "details": "The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin\u0027s settings",
  "id": "GHSA-6j5r-8vhm-p3x4",
  "modified": "2022-10-21T19:01:14Z",
  "published": "2022-10-17T19:00:30Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2834"
    },
    {
      "type": "WEB",
      "url": "https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37ae"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6P3H-R2C5-CH3V

Vulnerability from github – Published: 2022-05-24 17:30 – Updated: 2022-06-04 00:00
VLAI
Details

The local file inclusion vulnerability present in B&R SiteManager versions <9.2.620236042 allows authenticated users to impact availability of SiteManager instances.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2020-11642"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2020-10-15T15:15:00Z",
    "severity": "MODERATE"
  },
  "details": "The local file inclusion vulnerability present in B\u0026R SiteManager versions \u003c9.2.620236042 allows authenticated users to impact availability of SiteManager instances.",
  "id": "GHSA-6p3h-r2c5-ch3v",
  "modified": "2022-06-04T00:00:33Z",
  "published": "2022-05-24T17:30:42Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11642"
    },
    {
      "type": "WEB",
      "url": "https://us-cert.cisa.gov/ics/advisories/icsa-20-273-03"
    },
    {
      "type": "WEB",
      "url": "https://www.br-automation.com/downloads_br_productcatalogue/assets/1600003183751-de-original-1.0.pdf"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6P6H-9JG2-W75J

Vulnerability from github – Published: 2025-07-17 18:31 – Updated: 2025-07-24 21:30
VLAI
Details

OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerability allows attackers to obtain the password of the background administrator and further obtain database permissions.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-41566"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-07-17T16:15:34Z",
    "severity": "HIGH"
  },
  "details": "OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerability allows attackers to obtain the password of the background administrator and further obtain database permissions.",
  "id": "GHSA-6p6h-9jg2-w75j",
  "modified": "2025-07-24T21:30:37Z",
  "published": "2025-07-17T18:31:13Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41566"
    },
    {
      "type": "WEB",
      "url": "https://gist.github.com/night-0p/668fc88385d4f60feb90b7fcef8443b1"
    },
    {
      "type": "WEB",
      "url": "https://github.com/night-0p/anh/blob/main/Landray%20OA/FileDownload.md"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6Q4V-9F44-VXXX

Vulnerability from github – Published: 2024-11-27 03:31 – Updated: 2025-03-05 15:30
VLAI
Details

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-53676"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-22",
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-11-27T01:15:05Z",
    "severity": "CRITICAL"
  },
  "details": "A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.",
  "id": "GHSA-6q4v-9f44-vxxx",
  "modified": "2025-03-05T15:30:50Z",
  "published": "2024-11-27T03:31:36Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53676"
    },
    {
      "type": "WEB",
      "url": "https://github.com/pwnfuzz/POCs/tree/main/CVE-2024-53676"
    },
    {
      "type": "WEB",
      "url": "https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US\u0026docId=hpesbgn04731en_us"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6R67-R3JM-88P4

Vulnerability from github – Published: 2022-05-13 01:11 – Updated: 2025-10-22 00:31
VLAI
Details

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2017-16651"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2017-11-09T14:29:00Z",
    "severity": "HIGH"
  },
  "details": "Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host\u0027s filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings\u0026_action=upload-display\u0026_from=timezone requests.",
  "id": "GHSA-6r67-r3jm-88p4",
  "modified": "2025-10-22T00:31:29Z",
  "published": "2022-05-13T01:11:29Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-16651"
    },
    {
      "type": "WEB",
      "url": "https://github.com/roundcube/roundcubemail/issues/6026"
    },
    {
      "type": "WEB",
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.1.10"
    },
    {
      "type": "WEB",
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.2.7"
    },
    {
      "type": "WEB",
      "url": "https://github.com/roundcube/roundcubemail/releases/tag/1.3.3"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2017/11/msg00039.html"
    },
    {
      "type": "WEB",
      "url": "https://roundcube.net/news/2017/11/08/security-updates-1.3.3-1.2.7-and-1.1.10"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-16651"
    },
    {
      "type": "WEB",
      "url": "https://www.debian.org/security/2017/dsa-4030"
    },
    {
      "type": "WEB",
      "url": "http://packetstormsecurity.com/files/161226/Roundcube-Webmail-1.2-File-Disclosure.html"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/101793"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6VGR-R2FG-P38Q

Vulnerability from github – Published: 2026-08-27 21:31 – Updated: 2026-08-28 21:31
VLAI
Details

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This may disclose files accessible to the Alloy process, including its projected Kubernetes service account token, potentially granting the attacker Alloy’s Kubernetes permissions. Exploitation requires ServiceMonitor write access and lower privileges than Alloy’s service account.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-75889"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-27T20:18:37Z",
    "severity": "HIGH"
  },
  "details": "Grafana Alloy\u2019s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This may disclose files accessible to the Alloy process, including its projected Kubernetes service account token, potentially granting the attacker Alloy\u2019s Kubernetes permissions. Exploitation requires ServiceMonitor write access and lower privileges than Alloy\u2019s service account.",
  "id": "GHSA-6vgr-r2fg-p38q",
  "modified": "2026-08-28T21:31:07Z",
  "published": "2026-08-27T21:31:52Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75889"
    },
    {
      "type": "WEB",
      "url": "https://grafana.com/security/security-advisories/cve-2026-75889"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-6VMP-9X58-MV62

Vulnerability from github – Published: 2022-05-13 01:07 – Updated: 2022-05-13 01:07
VLAI
Details

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2017-2622"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-200",
      "CWE-552"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2018-07-27T13:29:00Z",
    "severity": "MODERATE"
  },
  "details": "An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.",
  "id": "GHSA-6vmp-9x58-mv62",
  "modified": "2022-05-13T01:07:33Z",
  "published": "2022-05-13T01:07:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-2622"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2017:1584"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/CVE-2017-2622"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1420992"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2622"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

Mitigation
Implementation System Configuration Operation

When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.

CAPEC-150: Collect Data from Common Resource Locations

An adversary exploits well-known locations for resources for the purposes of undermining the security of the target. In many, if not most systems, files and resources are organized in a default tree structure. This can be useful for adversaries because they often know where to look for resources or files that are necessary for attacks. Even when the precise location of a targeted resource may not be known, naming conventions may indicate a small area of the target machine's file tree where the resources are typically located. For example, configuration files are normally stored in the /etc director on Unix systems. Adversaries can take advantage of this to commit other types of attacks.

CAPEC-639: Probe System Files

An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive information in a file that is not protected by proper access control, then an adversary can access the file and search for sensitive information.