Описание
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.
EPSS
Процентиль: 0%
0.00007
Низкий
5.7 Medium
CVSS3
Дефекты
CWE-696
Связанные уязвимости
CVSS3: 5.7
github
8 месяцев назад
In WhiteBeam 0.2.0 through 0.2.1 before 0.2.2, a user with local access to a server can bypass the allow-list functionality because a file can be truncated in the OpenFileDescriptor action before the VerifyCanWrite action is performed.
EPSS
Процентиль: 0%
0.00007
Низкий
5.7 Medium
CVSS3
Дефекты
CWE-696