endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2022-1304 | e2fsprogs (CWE-125) #17

Open mgulter opened 2 years ago

mgulter commented 2 years ago

A high severity vulnerability has been discovered in your project.

Project Name: IssueTest

Scanner Name: trivy

Cwe ID: 125

Cwe Name: Out-of-bounds Read

Cwe Link: https://cwe.mitre.org/data/definitions/125.html

CVE ID: CVE-2022-1304

Target: nginx:latest (debian 11.3)

Packages:

References:

Training(Secure Code Warrior):

Tool Description: An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.

Custom Description: NEW ENDPOINT TEST