Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44512

Опубликовано: 07 дек. 2021
Источник: nvd
CVSS3: 7
CVSS2: 4.4
EPSS Низкий

Описание

World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tmate:tmate-ssh-server:*:*:*:*:*:*:*:*
Версия до 2.3.0 (включая)

EPSS

Процентиль: 9%
0.00032
Низкий

7 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7
ubuntu
около 4 лет назад

World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.

CVSS3: 7
debian
около 4 лет назад

World-writable permissions on the /tmp/tmate/sessions directory in tma ...

CVSS3: 7
github
около 4 лет назад

World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.

EPSS

Процентиль: 9%
0.00032
Низкий

7 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-732