Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mvxp-vg38-gq5c

Опубликовано: 08 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally widen the permissions for the target file, leaving the updated file accessible to more users than intended.

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally widen the permissions for the target file, leaving the updated file accessible to more users than intended.

EPSS

Процентиль: 42%
0.00195
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
redhat
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
nvd
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.

CVSS3: 9.8
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 3 лет назад

When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files ...

EPSS

Процентиль: 42%
0.00195
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276