Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8j4-pwp4-c58m

Опубликовано: 03 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.2

Описание

Improper Access Control in stitionai/devika

Improper Access Control in stitionai/devika

EPSS

Процентиль: 26%
0.00088
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-22
CWE-284

Связанные уязвимости

CVSS3: 6.2
nvd
больше 1 года назад

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.

EPSS

Процентиль: 26%
0.00088
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-22
CWE-284