Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9x7-4mx4-prwq

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2

Описание

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without the "O_NOFOLLOW" flag. A local attacker can exploit this by creating a symlink at the expected log file path pointing to a sensitive file, causing dool to truncate and overwrite the target file with log data, which is especially impactful if dool is run with elevated privileges. The issue was addressed by pull request #116

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without the "O_NOFOLLOW" flag. A local attacker can exploit this by creating a symlink at the expected log file path pointing to a sensitive file, causing dool to truncate and overwrite the target file with log data, which is especially impactful if dool is run with elevated privileges. The issue was addressed by pull request #116

EPSS

Процентиль: 5%
0.00152
Низкий

2 Low

CVSS4

Дефекты

CWE-59

Связанные уязвимости

nvd
12 дней назад

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without the "O_NOFOLLOW" flag. A local attacker can exploit this by creating a symlink at the expected log file path pointing to a sensitive file, causing dool to truncate and overwrite the target file with log data, which is especially impactful if dool is run with elevated privileges. The issue was addressed by pull request #116

debian
12 дней назад

Dool in versions up to 1.3.8 is vulnerable tosymlink following when th ...

EPSS

Процентиль: 5%
0.00152
Низкий

2 Low

CVSS4

Дефекты

CWE-59