Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3ph3-5vg6-324h

Опубликовано: 21 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.

In Soffid Console 3.5.38 before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code in the Sync Server and compromise security.

EPSS

Процентиль: 4%
0.00018
Низкий

8.5 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 2.5
nvd
10 месяцев назад

In Soffid Console 3.6.31 before 3.6.32, authorization to use the pam service is mishandled.

EPSS

Процентиль: 4%
0.00018
Низкий

8.5 High

CVSS3

Дефекты

CWE-863