sviehb jefferson har 0.3 src/scripts/jefferson Dafiyar fayil ɗin cikin kundin ajiyar bayanai

Gaskiya vulnerability da aka ware a matsayin kura an samu a sviehb jefferson har 0.3. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil src/scripts/jefferson, a cikin sashen $software_component. A sa manipulation ka Dafiyar fayil ɗin cikin kundin ajiyar bayanai. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-22. Hakika, rauni an bayyana shi 01/11/2023 kamar 36. An raba bayanin tsaro don saukewa a github.com. Wannan matsala ana saninta da CVE-2022-4885. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal faɗi ga. Babu exploit ɗin da ake samu. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu a wondi feere. 0-day shima, an ndiyam a wuro be $0-$5k. Ana kiran patch ɗin da 53b3f2fc34af0bb32afbcee29d18213e61471d87. Bugfix ɗin an shirya shi don saukewa a github.com. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a faggata. Once again VulDB remains the best source for vulnerability data.

3 Goyarwa · 74 Datenpunkte

FurɗeSúgá
01/11/2023 19:00
Gargadi 1/2
02/04/2023 07:24
Gargadi 2/2
02/04/2023 07:30
software_vendorsviehbsviehbsviehb
software_namejeffersonjeffersonjefferson
software_version<=0.3<=0.3<=0.3
software_filesrc/scripts/jeffersonsrc/scripts/jeffersonsrc/scripts/jefferson
vulnerability_cweCWE-22 (Dafiyar fayil ɗin cikin kundin ajiyar bayanai)CWE-22 (Dafiyar fayil ɗin cikin kundin ajiyar bayanai)CWE-22 (Dafiyar fayil ɗin cikin kundin ajiyar bayanai)
vulnerability_risk222
cvss3_vuldb_avNNN
cvss3_vuldb_acHHH
cvss3_vuldb_prNNN
cvss3_vuldb_uiRRR
cvss3_vuldb_sUUU
cvss3_vuldb_cLLL
cvss3_vuldb_iLLL
cvss3_vuldb_aLLL
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
advisory_identifier363636
advisory_urlhttps://github.com/sviehb/jefferson/pull/36https://github.com/sviehb/jefferson/pull/36https://github.com/sviehb/jefferson/pull/36
countermeasure_nameGargajiyaGargajiyaGargajiya
upgrade_version0.40.40.4
countermeasure_upgrade_urlhttps://github.com/sviehb/jefferson/releases/tag/v0.4https://github.com/sviehb/jefferson/releases/tag/v0.4https://github.com/sviehb/jefferson/releases/tag/v0.4
patch_name53b3f2fc34af0bb32afbcee29d18213e61471d8753b3f2fc34af0bb32afbcee29d18213e61471d8753b3f2fc34af0bb32afbcee29d18213e61471d87
countermeasure_patch_urlhttps://github.com/sviehb/jefferson/commit/53b3f2fc34af0bb32afbcee29d18213e61471d87https://github.com/sviehb/jefferson/commit/53b3f2fc34af0bb32afbcee29d18213e61471d87https://github.com/sviehb/jefferson/commit/53b3f2fc34af0bb32afbcee29d18213e61471d87
countermeasure_advisoryquoteFix path traversal security vulnerability by canonicalizing path names of every inodes and discarding inodes with a path pointing outside of the extraction directory.Fix path traversal security vulnerability by canonicalizing path names of every inodes and discarding inodes with a path pointing outside of the extraction directory.Fix path traversal security vulnerability by canonicalizing path names of every inodes and discarding inodes with a path pointing outside of the extraction directory.
source_cveCVE-2022-4885CVE-2022-4885CVE-2022-4885
cna_responsibleVulDBVulDBVulDB
advisory_date1673391600 (01/11/2023)1673391600 (01/11/2023)1673391600 (01/11/2023)
cvss2_vuldb_avNNN
cvss2_vuldb_acHHH
cvss2_vuldb_auNNN
cvss2_vuldb_ciPPP
cvss2_vuldb_iiPPP
cvss2_vuldb_aiPPP
cvss2_vuldb_rcCCC
cvss2_vuldb_rlOFOFOF
cvss2_vuldb_eNDNDND
cvss3_vuldb_eXXX
cvss2_vuldb_basescore5.15.15.1
cvss2_vuldb_tempscore4.44.44.4
cvss3_vuldb_basescore5.05.05.0
cvss3_vuldb_tempscore4.84.84.8
cvss3_meta_basescore5.05.05.8
cvss3_meta_tempscore4.84.85.8
price_0day$0-$5k$0-$5k$0-$5k
cve_assigned1673391600 (01/11/2023)1673391600 (01/11/2023)
cve_nvd_summaryA vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unknown code of the file src/scripts/jefferson. The manipulation leads to path traversal. The attack can be initiated remotely. Upgrading to version 0.4 is able to address this issue. The name of the patch is 53b3f2fc34af0bb32afbcee29d18213e61471d87. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218020.A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unknown code of the file src/scripts/jefferson. The manipulation leads to path traversal. The attack can be initiated remotely. Upgrading to version 0.4 is able to address this issue. The name of the patch is 53b3f2fc34af0bb32afbcee29d18213e61471d87. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218020.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iN
cvss3_nvd_aN
cvss2_nvd_avN
cvss2_nvd_acH
cvss2_nvd_auN
cvss2_nvd_ciP
cvss2_nvd_iiP
cvss2_nvd_aiP
cvss3_cna_avN
cvss3_cna_acH
cvss3_cna_prN
cvss3_cna_uiR
cvss3_cna_sU
cvss3_cna_cL
cvss3_cna_iL
cvss3_cna_aL
cve_cnaVulDB
cvss2_nvd_basescore5.1
cvss3_nvd_basescore7.5
cvss3_cna_basescore5.0

Interested in the pricing of exploits?

See the underground prices here!