Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34286
HistoryFeb 20, 2022 - 3:55 a.m.

Data Injection

2022-02-2003:55:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
data injection
snapd
vulnerability
apparmor policy

EPSS

0.001

Percentile

34.4%

github.com/snapcore/snapd is vulnerable to data injection. The vulnerability exists because snapd doesn’t properly validate content interface and layout paths which allows an attacker to inject and execute arbitrary AppArmor policy rules.