Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr9v-36r3-5pfh

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.

In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.

EPSS

Процентиль: 83%
0.01998
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.

EPSS

Процентиль: 83%
0.01998
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-367