Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-778w-44h6-45xq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.

EPSS

Процентиль: 21%
0.0007
Низкий

7.8 High

CVSS3

Дефекты

CWE-276
CWE-863

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.

EPSS

Процентиль: 21%
0.0007
Низкий

7.8 High

CVSS3

Дефекты

CWE-276
CWE-863