Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h2q7-whv7-5m3x

Опубликовано: 20 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

EPSS

Процентиль: 19%
0.00059
Низкий

7.8 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
nvd
больше 2 лет назад

SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the root user.

EPSS

Процентиль: 19%
0.00059
Низкий

7.8 High

CVSS3

Дефекты

CWE-732