Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-37360

Опубликовано: 30 июн. 2023
Источник: debian
EPSS Низкий

Описание

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pacparserfixed1.4.3-1package
pacparserno-dsabookwormpackage
pacparserno-dsabullseyepackage
pacparserno-dsabusterpackage

Примечания

  • https://github.com/manugarg/pacparser/security/advisories/GHSA-62q6-v997-f7v9

  • https://github.com/manugarg/pacparser/commit/0bf0636de624996fe202b51eec8a58abd774269e (v1.4.2)

EPSS

Процентиль: 16%
0.00051
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 2 лет назад

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

CVSS3: 5.9
nvd
больше 2 лет назад

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

CVSS3: 5.9
github
больше 2 лет назад

pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within enterprise security products).

EPSS

Процентиль: 16%
0.00051
Низкий