Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vgf-rq97-hm9p

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

EPSS

Процентиль: 3%
0.00016
Низкий

7.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.2
nvd
почти 4 года назад

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

EPSS

Процентиль: 3%
0.00016
Низкий

7.1 High

CVSS3

Дефекты

CWE-20