Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vmrj-vq2q-4f66

Опубликовано: 23 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Multiple versions of GlobalProtect-openconnect are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the --script=<script> parameter.

Multiple versions of GlobalProtect-openconnect are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the --script=<script> parameter.

EPSS

Процентиль: 77%
0.01048
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GUI Application. The way GlobalProtect-Openconnect is set up enables arbitrary users to execute commands as root by submitting the `--script=<script>` parameter.

EPSS

Процентиль: 77%
0.01048
Низкий

9.8 Critical

CVSS3