CVE-2023-23558
PoC —CVSS 3.1
6.3 medium
EPSS
<1%p24
Published
()
Modified
Description
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
- Vendors
- eternal terminal project
- Products
- eternal terminal
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.