Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwpr-86q7-7gmv

Опубликовано: 22 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.

qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.

EPSS

Процентиль: 19%
0.00061
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.

CVSS3: 5.5
nvd
около 6 лет назад

qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.

CVSS3: 5.5
debian
около 6 лет назад

qtnx 0.9 stores non-custom SSH keys in a world-readable configuration ...

EPSS

Процентиль: 19%
0.00061
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-312