Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-637c-5c76-f4m8

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

EPSS

Процентиль: 23%
0.00077
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 2.5
redhat
больше 9 лет назад

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

CVSS3: 4.7
nvd
больше 8 лет назад

authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race condition between the creation of the key, and the chmod to protect it.

EPSS

Процентиль: 23%
0.00077
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-362