Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3r4x-4pr5-j666

Опубликовано: 10 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.

EPSS

Процентиль: 0%
0.00075
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.5
nvd
5 месяцев назад

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.

EPSS

Процентиль: 0%
0.00075
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-732