Описание
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:qduoj:onlinejudge:2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00921
Низкий
9.9 Critical
CVSS3
9 Critical
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 9.9
github
больше 3 лет назад
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
EPSS
Процентиль: 76%
0.00921
Низкий
9.9 Critical
CVSS3
9 Critical
CVSS2
Дефекты
CWE-22