PT-2024-25950 · Wordops · Wordops

Nevercodecorrect

·

Published

2024-05-05

·

Updated

2024-11-01

·

CVE-2024-34528

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WordOps versions prior to 3.20.1
Description The issue is related to a TOCTOU race condition in the wo/cli/plugins/stack pref.py file. This occurs because the conf path os.open does not use a mode parameter during file creation, potentially allowing unauthorized access or modification of files.
Recommendations For WordOps versions prior to 3.20.1, update to version 3.20.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the wo/cli/plugins/stack pref.py file until a patch is available.

Fix

Race Condition

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-34528
GHSA-23QQ-P4GQ-GC2G
PYSEC-2024-175

Affected Products

Wordops