logo

CVE-2020-27348 snapcraft

Package

Manager: pip
Name: snapcraft
Vulnerable Version: >=0 <4.4.4

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L

CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

EPSS: 0.00118 pctl0.31279

Details

snapcraft Access Restriction Bypass In some conditions, a snap package built by snapcraft includes the current directory in `LD_LIBRARY_PATH`, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and prior to 2.43.1+18.04.1.

Metadata

Created: 2022-05-24T17:35:23Z
Modified: 2024-10-23T18:48:17Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qxm5-vx5j-pp6w/GHSA-qxm5-vx5j-pp6w.json
CWE IDs: ["CWE-427"]
Alternative ID: GHSA-qxm5-vx5j-pp6w
Finding: F098
Auto approve: 1