Описание
Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgt_env” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/jammy | needed | |
| esm-apps/xenial | ignored | end of ESM support, was needs-triage |
| esm-infra-legacy/trusty | needs-triage | |
| jammy | needed | |
| noble | DNE | |
| oracular | DNE | |
| plucky | DNE |
Показывать по
6.3 Medium
CVSS3
Связанные уязвимости
Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgt_env” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to.
Arbitrary directory creation or file deletion. In the find_file method ...
Salt allows arbitrary directory creation or file deletion
Уязвимость метода find_file системы управления конфигурациями и удалённого выполнения операций Salt, позволяющая нарушителю манипулировать структурами данных
6.3 Medium
CVSS3