endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2004-0971 | libkrb5-3 (CWE-1035) #78

Open cbilgin23 opened 1 year ago

cbilgin23 commented 1 year ago

Due Date: 2022-11-03

A low severity vulnerability has been discovered in your project.

Project Name: twrap-go

Scanner Name: trivy

Cwe ID: 1035

Cwe Name: Using Components with Known Vulnerabilities

Cwe Link: https://cwe.mitre.org/data/definitions/1035.html

CVE ID: CVE-2004-0971

Target: redis:latest (debian 11.5)

Packages:

References:

Kondukto Remediation 1: sdfsdfsdf

Tool Description: The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

Custom Description: test

Kondukto Link: http://79.kondukto.local/projects/634fe837a5be8478724352c4/vulns/appsec?page=1&perPage=15&id=in:6362476983e330d938697b28 Deeplink: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0971