Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwh3-jw96-rmr6

Опубликовано: 17 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below 10.8.2.33 allows attackers to execute arbitrary commands via unauthorized access to the Agent service.

Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions below 10.8.2.33 allows attackers to execute arbitrary commands via unauthorized access to the Agent service.

EPSS

Процентиль: 19%
0.0006
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-346

Связанные уязвимости

nvd
10 месяцев назад

Improper Verification of Source of a Communication Channel in Work Desktop for Mac versions 10.8.1.46 and earlier allows attackers to execute arbitrary commands via unauthorized access to the Agent service.  This has been remediated in Work Desktop for Mac version 10.8.2.33.

EPSS

Процентиль: 19%
0.0006
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-346