Логотип exploitDog
bind:"GHSA-6wxm-mpqj-6jpf" OR bind:"CVE-2024-45339"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-6wxm-mpqj-6jpf" OR bind:"CVE-2024-45339"

Количество 15

Количество 15

github логотип

GHSA-6wxm-mpqj-6jpf

7 месяцев назад

Insecure Temporary File usage in github.com/golang/glog

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2024-45339

7 месяцев назад

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2024-45339

7 месяцев назад

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2024-45339

7 месяцев назад

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2024-45339

7 месяцев назад

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2024-45339

7 месяцев назад

When logs are written to a widely-writable directory (the default), an ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0611-1

7 месяцев назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0580-1

7 месяцев назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02150-1

2 месяца назад

Security update for google-osconfig-agent

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02149-1

2 месяца назад

Security update for google-osconfig-agent

EPSS: Низкий
fstec логотип

BDU:2025-02785

7 месяцев назад

Уязвимость функции createInDir библиотеки glog языка программирования Golang, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20250814-08

23 дня назад

Уязвимость golang-github-glog-devel

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0623-1

7 месяцев назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0429-1

7 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0297-1

7 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6wxm-mpqj-6jpf

Insecure Temporary File usage in github.com/golang/glog

CVSS3: 7.1
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
redhat логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
nvd логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

CVSS3: 7.1
0%
Низкий
7 месяцев назад
msrc логотип
CVSS3: 7.1
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-45339

When logs are written to a widely-writable directory (the default), an ...

CVSS3: 7.1
0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0611-1

Security update for google-osconfig-agent

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0580-1

Security update for google-osconfig-agent

0%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02150-1

Security update for google-osconfig-agent

0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02149-1

Security update for google-osconfig-agent

0%
Низкий
2 месяца назад
fstec логотип
BDU:2025-02785

Уязвимость функции createInDir библиотеки glog языка программирования Golang, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

CVSS3: 7.1
0%
Низкий
7 месяцев назад
redos логотип
ROS-20250814-08

Уязвимость golang-github-glog-devel

CVSS3: 7.1
0%
Низкий
23 дня назад
suse-cvrf логотип
SUSE-SU-2025:0623-1

Security update for grafana

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0429-1

Security update for govulncheck-vulndb

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0297-1

Security update for govulncheck-vulndb

7 месяцев назад

Уязвимостей на страницу