Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-43451

Опубликовано: 03 нояб. 2022
Источник: nvd
CVSS3: 8.4
CVSS3: 6.5
EPSS Низкий

Описание

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*:*
Версия от 3.1 (включая) до 3.1.2 (включая)

EPSS

Процентиль: 12%
0.0004
Низкий

8.4 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-22

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other vulnerabilities it would allow an unprivileged process to gain full root privileges.

EPSS

Процентиль: 12%
0.0004
Низкий

8.4 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-22