Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-27294

Опубликовано: 29 фев. 2024
Источник: nvd
CVSS3: 7.3
CVSS3: 7.8
EPSS Низкий

Описание

dp-golang is a Puppet module for Go installations. Prior to 1.2.7, dp-golang could install files — including the compiler binary — with the wrong ownership when Puppet was run as root and the installed package was On macOS: Go version 1.4.3 through 1.21rc3, inclusive, go1.4-bootstrap-20170518.tar.gz, or go1.4-bootstrap-20170531.tar.gz. The user and group specified in Puppet code were ignored for files within the archive. dp-puppet version 1.2.7 will recreate installations if the owner or group of any file or directory within that installation does not match the requested owner or group

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:danielparks:dp-golang:*:*:*:*:*:puppet:*:*
Версия до 1.2.7 (исключая)

EPSS

Процентиль: 32%
0.00122
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-732
CWE-732

EPSS

Процентиль: 32%
0.00122
Низкий

7.3 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-732
CWE-732