Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7c8-fmh5-w5pf

Опубликовано: 21 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.

The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.

EPSS

Процентиль: 95%
0.19111
Средний

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 6.8
nvd
около 4 лет назад

The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.

CVSS3: 6.8
fstec
около 4 лет назад

Уязвимость реализации компонента управления «Log alert to a file» программного обеспечения сетевого мониторинга SolarWinds Orion Platform, позволяющая нарушителю повысить свои привилегии или выполнить произвольный код

EPSS

Процентиль: 95%
0.19111
Средний

7.2 High

CVSS3

Дефекты

CWE-434