Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p869-hg26-w7c6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

EPSS

Процентиль: 59%
0.00387
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

EPSS

Процентиль: 59%
0.00387
Низкий

Дефекты

CWE-276