Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jmhx-fqfh-838h

Опубликовано: 29 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.

Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.

EPSS

Процентиль: 33%
0.0013
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.3
nvd
около 3 лет назад

Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files located in that folder.

EPSS

Процентиль: 33%
0.0013
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-732