Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27px-qpmj-qg38

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Paste Script has improper group memberships permissions

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

Пакеты

Наименование

pastescript

pip
Затронутые версииВерсия исправления

< 2.0.1

2.0.1

Наименование

paste

pip
Затронутые версииВерсия исправления

< 1.7.5.1

1.7.5.1

EPSS

Процентиль: 78%
0.01239
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
больше 13 лет назад

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

redhat
больше 13 лет назад

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

nvd
больше 13 лет назад

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

debian
больше 13 лет назад

Paste Script 1.7.5 and earlier does not properly set group memberships ...

oracle-oval
почти 13 лет назад

ELSA-2012-1206: python-paste-script security update (MODERATE)

EPSS

Процентиль: 78%
0.01239
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3