Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv8r-66p7-3q68

Опубликовано: 21 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

EPSS

Процентиль: 25%
0.00322
Низкий

7.6 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.6
ubuntu
3 месяца назад

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

CVSS3: 7.6
nvd
3 месяца назад

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

CVSS3: 7.6
debian
3 месяца назад

Incomplete sanitization of extended attribute (EA) path components in ...

EPSS

Процентиль: 25%
0.00322
Низкий

7.6 High

CVSS3

Дефекты

CWE-22