Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
CVSS Information
N/A
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
sos-collector 安全漏洞
Vulnerability Description
sos-collector是一款用于从多个节点收集sosreport的实用程序。 sos-collector中存在安全漏洞,该漏洞源于程序未能妥当地设置新建文件的默认权限,导致本地用户可读取该工具创建的所有文件。本地攻击者可通过等待合法用户运行sos-collector利用该漏洞窃取/var/tmp目录中收集的数据。
CVSS Information
N/A
Vulnerability Type
N/A