Описание
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.2.1 (включая)
cpe:2.3:a:thecodingmachine:gotenberg:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00387
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-276
Связанные уязвимости
github
больше 3 лет назад
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
EPSS
Процентиль: 59%
0.00387
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-276