Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0219

Опубликовано: 31 янв. 2024
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
EPSS Низкий

Описание

In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:progress:telerik_justdecompile:*:*:*:*:*:*:*:*
Версия до 2019.1.118.0 (включая)

EPSS

Процентиль: 71%
0.00694
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
github
около 2 лет назад

In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

EPSS

Процентиль: 71%
0.00694
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo