Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64gg-ww65-9f92

Опубликовано: 08 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.9

Описание

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact on confidentiality and availability of the system.

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact on confidentiality and availability of the system.

EPSS

Процентиль: 1%
0.00011
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.9
nvd
7 месяцев назад

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact on confidentiality and availability of the system.

CVSS3: 6.9
fstec
7 месяцев назад

Уязвимость утилиты сжатия и распаковки файлов SAPCAR, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.00011
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-266