Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grp6-p35v-pgfx

Опубликовано: 26 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.

EPSS

Процентиль: 31%
0.00114
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
nvd
почти 4 года назад

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.

EPSS

Процентиль: 31%
0.00114
Низкий

7.1 High

CVSS3

Дефекты

CWE-59