Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gq47-h9vq-4rp9

Опубликовано: 17 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM.

An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM.

EPSS

Процентиль: 9%
0.00031
Низкий

8.5 High

CVSS4

Дефекты

CWE-267

Связанные уязвимости

nvd
10 месяцев назад

An attacker with knowledge of creating user accounts during VM deployment on Google Cloud Platform (GCP) using the OS Login feature, can login via SSH gaining command-line control of the operating system. This allows an attacker to gain access to sensitive data stored on the VM, install malicious software, and disrupt or disable the functionality of the VM.

CVSS3: 5.5
fstec
11 месяцев назад

Уязвимость программных средств управления данными Delphix Continuous Data и Delphix Continuous Compliance, связанная с некорректным присвоением привилегий, позволяющая нарушителю получить контроль над командной строкой операционной системы

EPSS

Процентиль: 9%
0.00031
Низкий

8.5 High

CVSS4

Дефекты

CWE-267