Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q7c2-6g86-6v93

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

EPSS

Процентиль: 62%
0.00431
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.9
ubuntu
почти 8 лет назад

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

CVSS3: 9.9
nvd
почти 8 лет назад

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

CVSS3: 9.9
debian
почти 8 лет назад

The build package before 20171128 did not check directory names during ...

suse-cvrf
почти 7 лет назад

Security update for build

suse-cvrf
почти 7 лет назад

Security update for build

EPSS

Процентиль: 62%
0.00431
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20