Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mwq-x2m3-qxc6

Опубликовано: 16 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 21%
0.00067
Низкий

8.4 High

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 7.8
nvd
почти 2 года назад

In startInstall of UpdateFetcher.java, there is a possible way to trigger a malicious config update due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

EPSS

Процентиль: 21%
0.00067
Низкий

8.4 High

CVSS3

Дефекты

CWE-693