Instalator Windows HashiCorp Vagrant dla niestandardowej lokalizacji wykorzystywał niezabezpieczoną ścieżkę podatną na junction attack, co mogło prowadzić do nieautoryzowanych zapisów w systemie plików. Problem naprawiono w Vagrant 2.4.0.
▸ Pokaż oryginał (EN)
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:NHashicorp Vagrant
APPHashicorp< 2.4.0
Powiązane podatności
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on...
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is ...
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can s...
HashiCorp Vault: RCE przez uprzywilejowanego operatora via sys/audit
HashiCorp go-getter: argument injection przy odkrywaniu zdalnych gałęzi Git