Описание
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
Ссылки
- ExploitMitigationVendor Advisory
- Third Party Advisory
- ExploitMitigationVendor Advisory
Уязвимые конфигурации
EPSS
8.8 High
CVSS3
Дефекты
Связанные уязвимости
openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access methods like pathlib.Path and io.open. Attackers can import pathlib or io modules to read and write arbitrary files, completely bypassing the restricted_open file access controls.
Уязвимость файла openssl_encrypt/modules/plugin_system/plugin_sandbox.py библиотеки openssl_encrypt языка программирования Python, позволяющая нарушителю получить несанкционированный доступ на чтение и запись произвольных файлов
EPSS
8.8 High
CVSS3