Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4fr-qhv5-6jfq

Опубликовано: 17 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 131.0.6778.268 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

EPSS

Процентиль: 52%
0.00287
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
10 месяцев назад

Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker with a registered Gerrit account to inject malicious code into ChromeOS projects and potentially achieve Remote Code Execution and Denial of Service via editing trusted pipelines by insufficient access controls and misconfigurations in Gerrit's project.config.

CVSS3: 8.8
fstec
больше 1 года назад

Уязвимость функции bitmap_ip_uadt() операционной системы Google ChromeOS, позволяющая нарушителю обойти ограничения безопасности и выполнить произвольный код

EPSS

Процентиль: 52%
0.00287
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-284
CWE-94