Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-999v-p9fh-4w86

Опубликовано: 19 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

EPSS

Процентиль: 26%
0.00091
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.7
nvd
больше 1 года назад

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the Zammad user).

CVSS3: 6.7
debian
больше 1 года назад

In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with ...

EPSS

Процентиль: 26%
0.00091
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-94