Описание
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- US Government Resource
- PatchVendor Advisory
- PatchVendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.2_beta (включая)
Одно из
cpe:2.3:a:fraunhofer_fit:bscw:*:*:*:*:*:*:*:*
cpe:2.3:a:fraunhofer_fit:bscw:3.3:*:*:*:*:*:*:*
cpe:2.3:a:fraunhofer_fit:bscw:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:fraunhofer_fit:bscw:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:fraunhofer_fit:bscw:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:fraunhofer_fit:bscw:4.0.1_beta:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03174
Низкий
6.4 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and extracting a tar file with a symlink into the data-bag space.
EPSS
Процентиль: 87%
0.03174
Низкий
6.4 Medium
CVSS2
Дефекты
NVD-CWE-Other