Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grvj-7p65-qc92

Опубликовано: 30 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

EPSS

Процентиль: 1%
0.0001
Низкий

7 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7
nvd
5 дней назад

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

CVSS3: 7
fstec
6 дней назад

Уязвимость установщика агента для сборки и доставки данных в Elasticsearch или Logstash Elastic Beats, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.0001
Низкий

7 High

CVSS3

Дефекты

CWE-427