Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j3h2-4rr5-87p6

Опубликовано: 19 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 года назад

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVSS3: 8.8
fstec
около 1 года назад

Уязвимость образа Docker средства регистрации посылок и отправлений Incoming Goods Suite, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-250