Time-of-check Time-of-use (TOCTOU) Race Condition Affecting wordops package, versions [,3.21.0)
Threat Intelligence
EPSS
0.04% (11th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-WORDOPS-6809228
- published 6 May 2024
- disclosed 6 May 2024
- credit Unknown
Introduced: 6 May 2024
CVE-2024-34528 Open this link in a new tabHow to fix?
Upgrade wordops
to version 3.21.0 or higher.
Overview
wordops is an An essential toolset that eases server administration
Affected versions of this package are vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in stack_pref.py
, which sets the the conf_path
variable using os.open function
, and does not restrict the permissions on the resulting file. An attacker can exploit this to inject a malicious file which is subsequently executed.
References
CVSS Scores
version 3.1