Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-41958

Опубликовано: 25 нояб. 2022
Источник: nvd
CVSS3: 7.3
CVSS3: 7.8
EPSS Низкий

Описание

super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit 4d0d5966 and will be included in future releases. Users are advised to upgrade. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:super_xray_project:super_xray:*:*:*:*:*:*:*:*
Версия до 0.7 (исключая)

EPSS

Процентиль: 52%
0.00291
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-502

EPSS

Процентиль: 52%
0.00291
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-502