Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjj3-f3rf-jf7w

Опубликовано: 10 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.

EPSS

Процентиль: 23%
0.00079
Низкий

7.6 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.6
redhat
почти 2 года назад

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.

CVSS3: 7.6
nvd
почти 2 года назад

A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can use the vulnerability to disclose the confidential Snyk authentication token and to run arbitrary commands on OSH workers.

EPSS

Процентиль: 23%
0.00079
Низкий

7.6 High

CVSS3

Дефекты

CWE-78