Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56377

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия до 6.9.13-48 (исключая)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
Версия от 7.0.0-0 (включая) до 7.1.2-24 (исключая)

EPSS

Процентиль: 6%
0.00164
Низкий

3.3 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.3
ubuntu
3 месяца назад

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

CVSS3: 3.3
redhat
3 месяца назад

ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries.

CVSS3: 3.3
debian
3 месяца назад

ImageMagick before 7.1.2-24 contains an incorrect policy check that al ...

CVSS3: 3.3
redos
2 месяца назад

Уязвимость ImageMagick

CVSS3: 3.3
redos
2 месяца назад

Уязвимость ImageMagick7

EPSS

Процентиль: 6%
0.00164
Низкий

3.3 Low

CVSS3

Дефекты

CWE-22