Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x67m-xw25-vpg2

Опубликовано: 27 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 2.5

Описание

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the chmod and makedirs Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the chmod and makedirs Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

EPSS

Процентиль: 3%
0.00016
Низкий

2.5 Low

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 2.5
nvd
11 месяцев назад

In the Splunk App for Lookup File Editing versions below 4.0.5, a script in the app used the `chmod` and `makedirs` Python functions in a way that resulted in overly broad read and execute permissions. This could lead to improper access control for a low-privileged user.

EPSS

Процентиль: 3%
0.00016
Низкий

2.5 Low

CVSS3

Дефекты

CWE-732