Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmwg-pqhj-8m9m

Опубликовано: 04 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.4
nvd
больше 3 лет назад

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22