Количество 2
Количество 2
CVE-2021-40531
Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app.
GHSA-jf84-45wf-mjgm
Sketch before 75 mishandles external library feeds.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-40531 Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opened, without the com.apple.quarantine extended attribute. This results in remote code execution, as demonstrated by CommandString in a terminal profile to Terminal.app. | CVSS3: 9.8 | 7% Низкий | больше 4 лет назад | |
GHSA-jf84-45wf-mjgm Sketch before 75 mishandles external library feeds. | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад |
Уязвимостей на страницу