Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3pr6-5rrr-cqpq

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.

EPSS

Процентиль: 21%
0.0007
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-61

Связанные уязвимости

CVSS3: 5.5
nvd
6 месяцев назад

Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.

EPSS

Процентиль: 21%
0.0007
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-61