Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43782

Опубликовано: 22 сент. 2023
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cadence.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:falktx:cadence:*:*:*:*:*:*:*:*
Версия до 0.9.2 (включая)

EPSS

Процентиль: 4%
0.00018
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 5.5
github
больше 2 лет назад

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if it has been created by a local adversary before Cadence started. The adversary can then delete the file, disrupting Cadence.

EPSS

Процентиль: 4%
0.00018
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-668