Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frv5-mfr5-q7h5

Опубликовано: 07 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside the /tmp directory.

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside the /tmp directory.

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-91

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be changed to an absolute path; this will write the CSV file to that path inside the /tmp directory.

EPSS

Процентиль: 45%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-91