Privileges Escalation Affecting pastescript package, versions [,1.7.5)
Snyk CVSS
Attack Complexity
High
Threat Intelligence
EPSS
4.46% (93rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-PASTESCRIPT-40091
- published 8 Feb 2012
- disclosed 8 Feb 2012
- credit Clay Gerrard
Introduced: 8 Feb 2012
CVE-2012-0878 Open this link in a new tabOverview
pastescript
is a pluggable command-line frontend, including commands to setup package file layouts
Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.