CVE-2023-32303 - CVE House
Back to Database
Status published Medium CVE-2023-32303

Planet's secret file is created with excessive permissions

Vulnerability Description

Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a workaround, set the secret file permissions to only user read/write by hand.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32303

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

planet-client-python
Vulnerable Versions:
< 2.0.1

Timeline

Official Publish: May 12th, 2023
Last Modified: January 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Weaknesses (CWE)