Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6m9f-8vwq-97pm

Опубликовано: 02 мая 2022
Источник: github
Github: Прошло ревью

Описание

Smarty Does Not Consider Umask Values When Setting Permissions

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

Пакеты

Наименование

smarty/smarty

composer
Затронутые версииВерсия исправления

< 3.0.0-beta4

3.0.0-beta4

EPSS

Процентиль: 23%
0.00077
Низкий

Дефекты

CWE-281

Связанные уязвимости

ubuntu
почти 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

nvd
почти 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

debian
почти 15 лет назад

Smarty before 3.0.0 beta 4 does not consider the umask value when sett ...

EPSS

Процентиль: 23%
0.00077
Низкий

Дефекты

CWE-281