CVEbaza.plSłownik CWECWE-278
Common Weakness Enumeration

CWE-278

Insecure Preserved Inherited Permissions

Kategoria: VariantCVE: 7
Opis

Produkt dziedziczy zestaw niezabezpieczonych uprawnień dla obiektu, na przykład podczas kopiowania z pliku archiwum, bez świadomości lub zaangażowania użytkownika. Może to prowadzić do nieautoryzowanego dostępu do danych lub zasobów.

Description (EN)

A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.

Podatności CVE z CWE-278 (7)
8.8
CVSS
HIGH
CVE-2024-36538

Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

pub. 2024-07-24
8.8
CVSS
HIGH
CVE-2024-37769

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

pub. 2024-07-05
7.9
CVSS
HIGH
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

pub. 2023-08-04
7.3
CVSS
HIGH
CVE-2026-6265

Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1

pub. 2026-04-27
7.2
CVSS
HIGH
CVE-2025-2947

IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicious actor can use the command to elevate privileges to gain root access to the host operating system.

pub. 2025-04-17
6.7
CVSS
MEDIUM
CVE-2026-71477

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1001 and packaging/standalone/install.envsubst extracts and moves it without normalizing ownership, allowing a local user with those IDs to replace a root-installed executable, especially when MISE_INSTALL_PATH targets a shared location such as /usr/local/bin. This issue is fixed in version 2026.7.1.

pub. 2026-08-18
3.6
CVSS
LOW
CVE-2024-38531

Nix to menedżer pakietów dla Linuksa i innych systemów Unix zapewniający niezawodne i odtwarzalne zarządzanie pakietami. Proces budowania ma dostęp do katalogu budowania i może zmieniać jego uprawnienia. Złośliwy lokalny użytkownik może stworzyć binarny setuid w publicznie dostępnej lokalizacji, a następnie przejąć uprawnienia workera demona Nix i zhakować wszystkie przyszłe buildy. Problem został naprawiony w wersjach 2.23.1, 2.22.2, 2.21.3, 2.20.7, 2.19.5 i 2.18.4.

pub. 2024-06-28
Informacje
ID: CWE-278
Typ: Variant
Podatności: 7
MITRE CWE ↗
← Słownik CWE