Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21645

Опубликовано: 08 янв. 2024
Источник: nvd
CVSS3: 5.3
EPSS Высокий

Описание

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in pyload allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by pyload. Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act. This vulnerability has been patched in version 0.5.0b3.dev77.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pyload:pyload:*:*:*:*:*:*:*:*
Версия до 0.4.9 (включая)
cpe:2.3:a:pyload:pyload:0.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:pyload:pyload:0.5.0:beta2:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.73493
Высокий

5.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 5.3
debian
около 2 лет назад

pyLoad is the free and open-source Download Manager written in pure Py ...

CVSS3: 5.3
github
около 2 лет назад

pyload Log Injection vulnerability

EPSS

Процентиль: 99%
0.73493
Высокий

5.3 Medium

CVSS3

Дефекты

CWE-74