Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x7f-q6wr-wc4w

Опубликовано: 19 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

EPSS

Процентиль: 8%
0.00028
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 3.8
ubuntu
почти 4 года назад

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

CVSS3: 3.8
nvd
почти 4 года назад

snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. This could allow a local attacker to read information that should have been private. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1

CVSS3: 3.8
debian
почти 4 года назад

snapd 2.54.2 and earlier created ~/snap directories in user home direc ...

EPSS

Процентиль: 8%
0.00028
Низкий

Дефекты

CWE-276