Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-6917 | A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation. NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2022-41905 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory browsing enabled may be susceptible to Cross Site Scripting (XSS) attacks. This issue has been patched, users can upgrade to version 4.1.0. As a workaround, set `dir_browser.enable = False` in the configuration. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-2255 | A vulnerability was found in mod_wsgi. A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing. NVD description · AI analysis pending | 7.5 | <1% | PoC ×2 |
| — | |
| CVE-2018-11553 | SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php. SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url parameter to /login.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |