Логотип exploitDog
bind:"BDU:2025-02785" OR bind:"CVE-2024-45339"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-02785" OR bind:"CVE-2024-45339"

Количество 15

Количество 15

fstec логотип

BDU:2025-02785

12 месяцев назад

Уязвимость функции createInDir библиотеки glog языка программирования Golang, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20250814-08

5 месяцев назад

Уязвимость golang-github-glog-devel

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2024-45339

12 месяцев назад

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2024-45339

12 месяцев назад

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2024-45339

12 месяцев назад

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2024-45339

11 месяцев назад

Vulnerability when creating log files in github.com/golang/glog

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2024-45339

12 месяцев назад

When logs are written to a widely-writable directory (the default), an ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0611-1

11 месяцев назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0580-1

11 месяцев назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02150-1

7 месяцев назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02149-1

7 месяцев назад

Security update for google-osconfig-agent

EPSS: Низкий
github логотип

GHSA-6wxm-mpqj-6jpf

12 месяцев назад

Insecure Temporary File usage in github.com/golang/glog

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0623-1

11 месяцев назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0429-1

11 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0297-1

12 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-02785

Уязвимость функции createInDir библиотеки glog языка программирования Golang, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.1
0%
Низкий
12 месяцев назад
redos логотип
ROS-20250814-08

Уязвимость golang-github-glog-devel

CVSS3: 7.1
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
redhat логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
0%
Низкий
12 месяцев назад
msrc логотип
CVE-2024-45339

Vulnerability when creating log files in github.com/golang/glog

CVSS3: 7.1
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an ...

CVSS3: 7.1
0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0611-1

Security update for google-osconfig-agent

0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0580-1

Security update for google-osconfig-agent

0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02150-1

Security update for google-osconfig-agent

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02149-1

Security update for google-osconfig-agent

0%
Низкий
7 месяцев назад
github логотип
GHSA-6wxm-mpqj-6jpf

Insecure Temporary File usage in github.com/golang/glog

CVSS3: 7.1
0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0623-1

Security update for grafana

11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0429-1

Security update for govulncheck-vulndb

11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0297-1

Security update for govulncheck-vulndb

12 месяцев назад

Уязвимостей на страницу