PT-2009-5888 · Unknown · Back In Time
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Back In Time version 0.9.26
Description
The issue allows local users to obtain sensitive information or interfere with backup integrity. This is due to the
common/snapshots.py file changing certain permissions to 0777 before deleting files in an old backup snapshot, enabling users to read or modify these files.Recommendations
For version 0.9.26, consider restricting access to the
common/snapshots.py file until a patch is available, or avoid using the affected backup functionality to minimize the risk of exploitation.Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Back In Time