Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vpqp-hx68-p2wx

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.2

Описание

Improper Link Resolution Before File Access in Suds

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

Пакеты

Наименование

suds

pip
Затронутые версииВерсия исправления

<= 0.4

1.0.0

Наименование

suds-py3

pip
Затронутые версииВерсия исправления

< 1.4.4.1

1.4.4.1

EPSS

Процентиль: 43%
0.00558
Низкий

6.9 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

ubuntu
почти 13 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

redhat
около 13 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

nvd
почти 13 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

debian
почти 13 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users ...

suse-cvrf
почти 10 лет назад

Security update for python-suds-jurko

EPSS

Процентиль: 43%
0.00558
Низкий

6.9 Medium

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-59