Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-41950
HistoryNov 22, 2022 - 12:00 a.m.

CVE-2022-41950 Privilege Escalation Vulnerability by wrong chmod param

2022-11-2200:00:00
CWE-250
GitHub_M
www.cve.org
4
cve-2022-41950
privilege escalation
vulnerability
super-xray
gui alternative
xray permissions
linux
mac os
upgrade

CVSS3

6.4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta.

CNA Affected

[
  {
    "vendor": "4ra1n",
    "product": "super-xray",
    "versions": [
      {
        "version": "< 0.3-beta",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2022-41950