Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q96q-h836-9q4h

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

EPSS

Процентиль: 43%
0.00208
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 5.9
nvd
больше 3 лет назад

Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A physical attacker with general user privilege can modify the log file property to a symbolic link that points to arbitrary system file, causing the logging function to overwrite the system file and disrupt the system.

EPSS

Процентиль: 43%
0.00208
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-59