Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvg7-xxgr-rgpc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

EPSS

Процентиль: 55%
0.00326
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 7.1
nvd
больше 5 лет назад

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

EPSS

Процентиль: 55%
0.00326
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-23