Lucene search

K
redhatcveRedhat.comRH:CVE-2023-32032
HistoryJun 14, 2023 - 5:49 a.m.

CVE-2023-32032

2023-06-1405:49:22
redhat.com
access.redhat.com
9
vulnerability
dotnet
tarfile
elevation of privilege
extraction directory argument

6.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

0.001 Low

EPSS

Percentile

47.0%

A vulnerability was found in dotnet. This issue can cause an elevation of privilege when the TarFile.ExtractToDirectory ignores the extraction directory argument.

6.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H

0.001 Low

EPSS

Percentile

47.0%