Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crwr-hcrm-rq6f

Опубликовано: 22 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

EPSS

Процентиль: 24%
0.00078
Низкий

7.8 High

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 4 лет назад

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

CVSS3: 7.8
nvd
около 4 лет назад

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option. This affects Ubuntu, Debian, and Gentoo.

CVSS3: 7.8
debian
около 4 лет назад

USBView 2.1 before 2.2 allows some local users (e.g., ones logged in v ...

EPSS

Процентиль: 24%
0.00078
Низкий

7.8 High

CVSS3

Дефекты

CWE-287
CWE-306