Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w46-j5rx-g56g

Опубликовано: 22 янв. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

pytest has vulnerable tmpdir handling

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Пакеты

Наименование

pytest

pip
Затронутые версииВерсия исправления

< 9.0.3

9.0.3

EPSS

Процентиль: 4%
0.0014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-379

Связанные уязвимости

CVSS3: 6.8
ubuntu
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
redhat
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
nvd
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

CVSS3: 6.8
debian
7 месяцев назад

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytes ...

suse-cvrf
4 месяца назад

Security update for python-pytest

EPSS

Процентиль: 4%
0.0014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-379