CVE-2018-16494 Information
Jun 07, 2022
cve
Description
In VOS and overly permissive �mask\ may allow for authorized users of the server to gain unauthorized access through insecure file permissions that can result in an arbitrary read write or execution of newly created files and directories. Insecure umask setting was present throughout the Versa servers.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://hackerone.com/reports/1168191
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: