Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpqp-hx68-p2wx

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.2

Описание

Improper Link Resolution Before File Access in Suds

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

Пакеты

Наименование

suds

pip
Затронутые версииВерсия исправления

<= 0.4

1.0.0

Наименование

suds-py3

pip
Затронутые версииВерсия исправления

< 1.4.4.1

1.4.4.1

EPSS

Процентиль: 34%
0.00135
Низкий

6.9 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

ubuntu
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

redhat
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

nvd
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

debian
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users ...

suse-cvrf
больше 9 лет назад

Security update for python-suds-jurko

EPSS

Процентиль: 34%
0.00135
Низкий

6.9 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-59