Описание
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
Ссылки
- Broken LinkThird Party Advisory
- Broken LinkThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.1.12 (включая)
cpe:2.3:a:chocolatey:chocolatey_php:*:*:*:*:*:*:*:*
EPSS
Процентиль: 30%
0.00114
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-732
CWE-732
Связанные уязвимости
CVSS3: 4.3
github
около 3 лет назад
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
EPSS
Процентиль: 30%
0.00114
Низкий
4.3 Medium
CVSS3
Дефекты
CWE-732
CWE-732