Описание
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- ExploitMailing ListPatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitMailing ListPatchThird Party Advisory
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
snap-confine in snapd before 2.38 incorrectly set the ownership of a s ...
snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
EPSS
7.5 High
CVSS3
5 Medium
CVSS2