Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)
Vulnerability Description
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Laravel Valet 安全漏洞
Vulnerability Description
Laravel Valet是https://laravel.com/开源的一个PHP开发框架。 Laravel Valet 1.1.4版本至2.0.3版本存在安全漏洞,该漏洞源于允许用户修改具有root权限的valet命令,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A