Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69hj-5jh6-6q99

Опубликовано: 16 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 6.1

Описание

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.

EPSS

Процентиль: 14%
0.00229
Низкий

7 High

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.1
redhat
около 1 месяца назад

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.

CVSS3: 6.1
nvd
около 1 месяца назад

OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.

CVSS3: 6.1
debian
около 1 месяца назад

OpenTofu before 1.11.7 fails to validate existing symlinks in the prov ...

EPSS

Процентиль: 14%
0.00229
Низкий

7 High

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-59