Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh64-cxhv-8756

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.

EPSS

Процентиль: 81%
0.01616
Низкий

7 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7
nvd
около 5 лет назад

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.

EPSS

Процентиль: 81%
0.01616
Низкий

7 High

CVSS3

Дефекты

CWE-732