endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2016-2781 | coreutils (CWE-20) #4

Open mgulter opened 2 years ago

mgulter commented 2 years ago

A low severity vulnerability has been discovered in your project.

Project Name: IssueTest

Scanner Name: trivy

Cwe ID: 20

Cwe Name: Improper Input Validation

Cwe Link: https://cwe.mitre.org/data/definitions/20.html

CVE ID: CVE-2016-2781

Target: nginx:latest (debian 11.3)

Packages:

References:

Tool Description: chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Custom Description: test