Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95r5-fj57-4c78

Опубликовано: 29 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.

Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.

EPSS

Процентиль: 30%
0.00114
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder.

EPSS

Процентиль: 30%
0.00114
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732