Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86g4-g26w-p44c

Опубликовано: 21 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.4

Описание

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.

EPSS

Процентиль: 17%
0.00053
Низкий

8.4 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 8.4
nvd
почти 2 года назад

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.

EPSS

Процентиль: 17%
0.00053
Низкий

8.4 High

CVSS3

Дефекты

CWE-276