Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29526

Опубликовано: 11 мая 2022
Источник: redhat
CVSS3: 6.2

Описание

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

A flaw was found in the syscall.Faccessat function when calling a process by checking the group. This flaw allows an attacker to check the process group permissions rather than a member of the file's group, affecting system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and Servicesjenkins-operator-containerWill not fix
OpenShift Service Mesh 2.0servicemesh-grafanaWill not fix
OpenShift Service Mesh 2.0servicemesh-operatorWill not fix
OpenShift Service Mesh 2.0servicemesh-prometheusWill not fix
OpenShift Service Mesh 2.1servicemesh-proxyNot affected
Red Hat 3scale API Management Platform 23scale-apicast-operator-bundle-containerAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-operators-subscription-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/rcm-controller-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2thanos-containAffected
Red Hat Ansible Automation Platform 2receptorAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-269->CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2084085golang: syscall: faccessat checks wrong group

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 3 года назад

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

CVSS3: 5.3
nvd
почти 3 года назад

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

CVSS3: 5.3
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
почти 3 года назад

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Ass ...

suse-cvrf
около 3 лет назад

Security update for go1.17

6.2 Medium

CVSS3