Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6m9f-8vwq-97pm

Опубликовано: 02 мая 2022
Источник: github
Github: Прошло ревью

Описание

Smarty Does Not Consider Umask Values When Setting Permissions

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

Пакеты

Наименование

smarty/smarty

composer
Затронутые версииВерсия исправления

< 3.0.0-beta4

3.0.0-beta4

EPSS

Процентиль: 73%
0.01589
Низкий

Дефекты

CWE-281

Связанные уязвимости

ubuntu
больше 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

nvd
больше 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

debian
больше 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when sett ...

EPSS

Процентиль: 73%
0.01589
Низкий

Дефекты

CWE-281