endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2017-18018 | coreutils (CWE-362) #10

Open mgulter opened 2 years ago

mgulter commented 2 years ago

A low severity vulnerability has been discovered in your project.

Project Name: IssueTest

Scanner Name: trivy

Cwe ID: 362

Cwe Name: Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)

Cwe Link: https://cwe.mitre.org/data/definitions/362.html

CVE ID: CVE-2017-18018

Target: nginx:latest (debian 11.3)

Packages:

References:

Tool Description: In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

Custom Description: test