PT-2015-3543 · Jython · Jython

Lubomir Rintel

·

Publicado

2015-02-13

·

Atualizado

2022-05-14

·

CVE-2013-2027

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Jython versions 2.2.1 through 2.7.2b2 Jython versions prior to 2.7.2b3
Description The issue allows local users to bypass intended access restrictions via unspecified vectors, as Jython uses the current umask to set the privileges of the class cache files.
Recommendations For Jython versions 2.2.1 through 2.7.2b2, update to version 2.7.2b3 or later to resolve the issue. For Jython versions prior to 2.7.2b3, update to version 2.7.2b3 or later to resolve the issue.

Correção

Improper Preservation of Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2027
GHSA-9347-9W64-Q5WP
MGASA-2015-0096
OPENSUSE-SU-2024:10443-1

Produtos afetados

Jython