Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p293-86cr-rj34

Опубликовано: 07 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.

We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources.

We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later

EPSS

Процентиль: 6%
0.00023
Низкий

8.6 High

CVSS4

Дефекты

CWE-367

Связанные уязвимости

nvd
11 месяцев назад

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following versions: QVPN Device Client for Mac 2.2.5 and later Qsync for Mac 5.1.3 and later Qfinder Pro Mac 7.11.1 and later

EPSS

Процентиль: 6%
0.00023
Низкий

8.6 High

CVSS4

Дефекты

CWE-367