Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jxg9-387c-h784

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.

EPSS

Процентиль: 37%
0.00161
Низкий

7 High

CVSS3

Дефекты

CWE-434
CWE-94

Связанные уязвимости

CVSS3: 7
nvd
больше 6 лет назад

Code42 Enterprise and Crashplan for Small Business Client version 6.7 before 6.7.5, 6.8 before 6.8.8, and 6.9 before 6.9.4 allows eval injection. A proxy auto-configuration file, crafted by a lesser privileged user, may be used to execute arbitrary code at a higher privilege as the service user.

EPSS

Процентиль: 37%
0.00161
Низкий

7 High

CVSS3

Дефекты

CWE-434
CWE-94