Описание
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.
Ссылки
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.48.1 (включая)
cpe:2.3:a:rubocop_project:rubocop:*:*:*:*:*:*:*:*
EPSS
Процентиль: 20%
0.00063
Низкий
3.3 Low
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-668
Связанные уязвимости
CVSS3: 3.3
ubuntu
почти 9 лет назад
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.
CVSS3: 3.3
debian
почти 9 лет назад
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing loc ...
EPSS
Процентиль: 20%
0.00063
Низкий
3.3 Low
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-668