Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq8x-v7jw-v675

Опубликовано: 06 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Duplicate Advisory: users may append root to group listings

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-m65q-v92h-cm7q. This link is maintained to preserve external references.

Original Description

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listing when a user or process has fewer than exactly 1024 groups, leading to the erroneous inclusion of the root group in the access list.

Пакеты

Наименование

users

rust
Затронутые версииВерсия исправления

>= 0.8.0, <= 0.11.0

Отсутствует

7.1 High

CVSS3

Дефекты

CWE-266

7.1 High

CVSS3

Дефекты

CWE-266