info: name:/etc/shadow File Owner and Permission Check author: songyaeji severity: critical description:> The /etc/shadow file must only be readable by root. If its permissions or ownership are misconfigured, it can lead to exposure of password hashes, allowing offline cracking or privilege escalation. reference: - https://isms.kisa.or.kr/main/csap/notice/ - Cloud Vulnerability Assessment Guide (2024) by KISA tags: linux,local,shadow,permission,file,misconfiguration metadata: verified:true os: linux max-request:1 classification: cwe-id: CWE-732 cvss-metrics: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cvss-score:7.4