Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rq24-vhfq-6v9x

Опубликовано: 24 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).

EPSS

Процентиль: 78%
0.01098
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).

EPSS

Процентиль: 78%
0.01098
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-732