CVE-2025-22240 - CERT CVE
ID CVE-2025-22240
Sažetak Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgt_env” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to.
Reference
CVSS
Base: 6.3
Impact: 5.9
Exploitability:0.3
Pristup
VektorSloženostAutentikacija
LOCAL HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 13-06-2025 - 14:15
Objavljeno 13-06-2025 - 07:15