Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22422
HistoryJan 31, 2020 - 8:14 a.m.

Unsafe Identifiers

2020-01-3108:14:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.001

Percentile

38.7%

opencast-common is using unsafe identifier. The package allows the use of arbitrary identifiers for media packages and file systems, causing the identifier mismatch as an identifier may unintentionally be changed. When the identifiers are used for file system operations, an attacker can make use of the flaw to escape the directories and perform arbitrary file writes to other locations.

EPSS

0.001

Percentile

38.7%