Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xmgx-2283-p55h

Опубликовано: 19 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

EPSS

Процентиль: 78%
0.01102
Низкий

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

CVSS3: 7.8
nvd
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.

CVSS3: 7.8
debian
около 1 года назад

Qualys discovered that needrestart, before version 3.8, allows local a ...

CVSS3: 7.8
fstec
около 1 года назад

Уязвимость утилиты needrestart, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю выполнить произвольный код в контексте root-пользователя

EPSS

Процентиль: 78%
0.01102
Низкий

7.8 High

CVSS3

Дефекты

CWE-427