Lucene search

K
nvd[email protected]NVD:CVE-2011-4211
HistoryOct 30, 2011 - 7:55 p.m.

CVE-2011-4211

2011-10-3019:55:00
CWE-264
web.nvd.nist.gov
3

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

64.5%

The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of files, which allows local users to bypass intended access restrictions and create arbitrary files via ALLOWED_MODES and ALLOWED_DIRS changes within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.

Affected configurations

Nvd
Node
googleapp_engine_python_sdkRange1.5.3
OR
googleapp_engine_python_sdkMatch1.0.1
OR
googleapp_engine_python_sdkMatch1.0.2
OR
googleapp_engine_python_sdkMatch1.1.0
OR
googleapp_engine_python_sdkMatch1.1.1
OR
googleapp_engine_python_sdkMatch1.1.2
OR
googleapp_engine_python_sdkMatch1.1.3
OR
googleapp_engine_python_sdkMatch1.1.4
OR
googleapp_engine_python_sdkMatch1.1.5
OR
googleapp_engine_python_sdkMatch1.1.6
OR
googleapp_engine_python_sdkMatch1.1.7
OR
googleapp_engine_python_sdkMatch1.1.8
OR
googleapp_engine_python_sdkMatch1.1.9
OR
googleapp_engine_python_sdkMatch1.2.0
OR
googleapp_engine_python_sdkMatch1.2.1
OR
googleapp_engine_python_sdkMatch1.2.2
OR
googleapp_engine_python_sdkMatch1.2.3
OR
googleapp_engine_python_sdkMatch1.2.4
OR
googleapp_engine_python_sdkMatch1.2.5
OR
googleapp_engine_python_sdkMatch1.2.6
OR
googleapp_engine_python_sdkMatch1.2.7
OR
googleapp_engine_python_sdkMatch1.3.0
OR
googleapp_engine_python_sdkMatch1.3.1
OR
googleapp_engine_python_sdkMatch1.3.2
OR
googleapp_engine_python_sdkMatch1.3.3
OR
googleapp_engine_python_sdkMatch1.3.4
OR
googleapp_engine_python_sdkMatch1.3.5
OR
googleapp_engine_python_sdkMatch1.3.6
OR
googleapp_engine_python_sdkMatch1.3.7
OR
googleapp_engine_python_sdkMatch1.3.8
OR
googleapp_engine_python_sdkMatch1.4.0
OR
googleapp_engine_python_sdkMatch1.4.1
OR
googleapp_engine_python_sdkMatch1.4.2
OR
googleapp_engine_python_sdkMatch1.4.3
OR
googleapp_engine_python_sdkMatch1.5.0
OR
googleapp_engine_python_sdkMatch1.5.1
OR
googleapp_engine_python_sdkMatch1.5.2
VendorProductVersionCPE
googleapp_engine_python_sdk*cpe:2.3:a:google:app_engine_python_sdk:*:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.0.1cpe:2.3:a:google:app_engine_python_sdk:1.0.1:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.0.2cpe:2.3:a:google:app_engine_python_sdk:1.0.2:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.0cpe:2.3:a:google:app_engine_python_sdk:1.1.0:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.1cpe:2.3:a:google:app_engine_python_sdk:1.1.1:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.2cpe:2.3:a:google:app_engine_python_sdk:1.1.2:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.3cpe:2.3:a:google:app_engine_python_sdk:1.1.3:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.4cpe:2.3:a:google:app_engine_python_sdk:1.1.4:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.5cpe:2.3:a:google:app_engine_python_sdk:1.1.5:*:*:*:*:*:*:*
googleapp_engine_python_sdk1.1.6cpe:2.3:a:google:app_engine_python_sdk:1.1.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 371

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

64.5%

Related for NVD:CVE-2011-4211