Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-36078

Опубликовано: 19 мая 2024
Источник: debian
EPSS Низкий

Описание

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zammaditppackage

EPSS

Процентиль: 26%
0.00091
Низкий

Связанные уязвимости

CVSS3: 6.7
nvd
больше 1 года назад

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

CVSS3: 6.7
github
больше 1 года назад

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

EPSS

Процентиль: 26%
0.00091
Низкий