Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m375-vhrx-7rhv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.

EPSS

Процентиль: 58%
0.00359
Низкий

8.8 High

CVSS3

Дефекты

CWE-20
CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
почти 6 лет назад

An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.

EPSS

Процентиль: 58%
0.00359
Низкий

8.8 High

CVSS3

Дефекты

CWE-20
CWE-863