Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-18018 | coreutils (CWE-362) #71

Open
cbilgin23 opened this issue Nov 14, 2022 · 0 comments
Open

CVE-2017-18018 | coreutils (CWE-362) #71

cbilgin23 opened this issue Nov 14, 2022 · 0 comments
Assignees
Labels
bug Something isn't working KONDUKTO

Comments

@cbilgin23
Copy link

Due Date: 2022-11-03

A low severity vulnerability has been discovered in your project.

Project Name: twrap-go

Scanner Name: trivy

Cwe ID: 362

Cwe Name: Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)

Cwe Link: https://cwe.mitre.org/data/definitions/362.html

CVE ID: CVE-2017-18018

Target: redis:latest (debian 11.5)

Packages:

  • coreutils : 8.32-4 - Fixed Version:

References:

Tool Description: In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

Custom Description: asdas

Kondukto Link: http://79.kondukto.local/projects/634fe837a5be8478724352c4/vulns/appsec?page=1&perPage=15&id=in:636247699538740807b6fc45
Deeplink: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-18018

@cbilgin23 cbilgin23 added bug Something isn't working KONDUKTO labels Nov 14, 2022
@cbilgin23 cbilgin23 self-assigned this Nov 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working KONDUKTO
Projects
None yet
Development

No branches or pull requests

1 participant