Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-4563
HistoryDec 16, 2022 - 5:15 p.m.

Design/Logic Flaw

2022-12-1617:15:00
PRIOn knowledge base
www.prio-n.com
4
security vulnerability
freedom of the press
securedrop
local access
file gpg-agent.conf
symlink following
patch
identifier vdb-215972.

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of the file gpg-agent.conf. The manipulation leads to symlink following. Local access is required to approach this attack. The name of the patch is b0526a06f8ca713cce74b63e00d3730618d89691. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-215972.

CPENameOperatorVersion
securedroplt2.5.1

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.2%

Related for PRION:CVE-2022-4563