Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpw2-cwxg-4qv8

Опубликовано: 27 нояб. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

EPSS

Процентиль: 13%
0.00044
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 4 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 7.5
redhat
больше 4 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
nvd
больше 4 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
msrc
больше 4 лет назад

In Keepalived through 2.2.4 the D-Bus policy does not sufficiently restrict the message destination allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property

CVSS3: 5.4
debian
больше 4 лет назад

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently re ...

EPSS

Процентиль: 13%
0.00044
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-668