Privileges Escalation Affecting pastescript package, versions [,1.7.5)


0.0
medium

Snyk CVSS

    Attack Complexity High

    Threat Intelligence

    EPSS 4.46% (93rd percentile)
Expand this section
NVD
5.6 medium
Expand this section
Red Hat
5.6 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PYTHON-PASTESCRIPT-40091
  • published 8 Feb 2012
  • disclosed 8 Feb 2012
  • credit Clay Gerrard

Overview

pastescript is a pluggable command-line frontend, including commands to setup package file layouts Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.