漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
osquery: Unprivileged users can temporarily read file carve contents
Vulnerability Description
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
不安全的运行时授予权限
Vulnerability Title
osquery 权限许可和访问控制问题漏洞
Vulnerability Description
osquery osquery是osquery社区的一个基于 SQL 的操作系统检测、监控和分析软件。 osquery 5.23.1之前版本存在权限许可和访问控制问题漏洞,该漏洞源于进行中的文件提取目录未使用私有权限创建,可能导致非特权攻击者读取文件提取内容及任意文件读取。
CVSS Information
N/A
Vulnerability Type
N/A