Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3485-7x7c-qrw2

Опубликовано: 08 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

EPSS

Процентиль: 27%
0.00094
Низкий

7.8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backports SLE-15-SP4 allows local users to hijack the UNIX domain socket This issue affects: openSUSE Backports SLE-15-SP3 canna versions prior to canna-3.7p3-bp153.2.3.1. openSUSE Backports SLE-15-SP4 canna versions prior to 3.7p3-bp154.3.3.1. openSUSE Factory was also affected. Instead of fixing the package it was deleted there.

suse-cvrf
больше 3 лет назад

Security update for canna

suse-cvrf
больше 3 лет назад

Security update for canna

EPSS

Процентиль: 27%
0.00094
Низкий

7.8 High

CVSS3

Дефекты

CWE-284