Описание
lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on /tmp/my.cnf.#{target_host}.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:vladtheenterprising_project:vladtheenterprising:0.2.0:*:*:*:*:ruby:*:*
EPSS
Процентиль: 18%
0.00059
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 5.5
github
больше 3 лет назад
VladTheEnterprising allows local users to write to arbitrary files via a symlink attack
EPSS
Процентиль: 18%
0.00059
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-59