Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qvxv-pmq9-4q7g

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

High severity vulnerability that affects org.scala-lang:scala-compiler

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

Ссылки

Пакеты

Наименование

org.scala-lang:scala-compiler

maven
Затронутые версииВерсия исправления

< 2.10.7

2.10.7

Наименование

org.scala-lang:scala-compiler

maven
Затронутые версииВерсия исправления

>= 2.11.0, < 2.11.12

2.11.12

Наименование

org.scala-lang:scala-compiler

maven
Затронутые версииВерсия исправления

>= 2.12.0, < 2.12.4

2.12.4

EPSS

Процентиль: 33%
0.00128
Низкий

7.8 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

CVSS3: 6.7
redhat
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

CVSS3: 7.8
nvd
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

CVSS3: 7.8
debian
около 8 лет назад

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, ...

EPSS

Процентиль: 33%
0.00128
Низкий

7.8 High

CVSS3

Дефекты

CWE-732