Описание
Privilege escalation in beego
An issue was discovered in file profile.go. The MemProf and GetCPUProfile functions do not correctly check whether the created file exists. As a result attackers can launch attacks symlink attacks locally. Attackers can use this vulnerability to escalate privileges.
Пакеты
Наименование
github.com/beego/beego/v2
go
Затронутые версииВерсия исправления
>= 2.0.0, < 2.0.2
2.0.2
Наименование
github.com/beego/beego
go
Затронутые версииВерсия исправления
Отсутствует
Связанные уязвимости
CVSS3: 7.8
nvd
почти 4 года назад
An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.