Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4639-xx39-q537

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

EPSS

Процентиль: 65%
0.00485
Низкий

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
nvd
больше 4 лет назад

The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive uploaded via the 'Import Settings' feature, however this is not sufficient to protect against RCE as a race condition can be achieved in between the moment the file is extracted on the disk but not yet removed. It is a bypass of CVE-2020-24948.

EPSS

Процентиль: 65%
0.00485
Низкий

Дефекты

CWE-362