Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvxp-vg38-gq5c

Опубликовано: 08 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally widen the permissions for the target file, leaving the updated file accessible to more users than intended.

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally widen the permissions for the target file, leaving the updated file accessible to more users than intended.

EPSS

Процентиль: 39%
0.00173
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
redhat
больше 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
nvd
больше 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
msrc
больше 3 лет назад

When curl < 7.84.0 saves cookies alt-svc and hsts data to local files it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation it might accidentally *widen* the permissions for the target file leaving the updated file accessible to more users than intended.

CVSS3: 9.8
debian
больше 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files ...

EPSS

Процентиль: 39%
0.00173
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276