Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxfw-fpvf-77hw

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.

EPSS

Процентиль: 48%
0.00252
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.

CVSS3: 6.5
nvd
больше 9 лет назад

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.

CVSS3: 6.5
debian
больше 9 лет назад

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 a ...

EPSS

Процентиль: 48%
0.00252
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284