Количество 4
Количество 4
CVE-2026-74796
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
CVE-2026-74796
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
CVE-2026-74796
OpenTofu before 1.11.7 fails to validate existing symlinks in the prov ...
GHSA-69hj-5jh6-6q99
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-74796 OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree. | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-74796 OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree. | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-74796 OpenTofu before 1.11.7 fails to validate existing symlinks in the prov ... | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад | |
GHSA-69hj-5jh6-6q99 OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree. | CVSS3: 6.1 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу