漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Vagrant VMWare Utility installation files vulnerable to modification by unprivileged user
Vulnerability Description
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes. This vulnerability, CVE-2024-10228, was fixed in Vagrant VMWare Utility 1.0.23
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Vulnerability Type
关键资源的不正确权限授予
Vulnerability Title
Vagrant VMWare Utility 安全漏洞
Vulnerability Description
HashiCorp Vagrant VMware Utility是美国HashiCorp公司的一个实用程序服务。 Vagrant VMWare Utility 1.0.22及之前版本存在安全漏洞,该漏洞源于Windows安装程序针对自定义位置使用了非受保护路径,这可能被未授权用户修改,从而引入未经授权的文件系统写入。
CVSS Information
N/A
Vulnerability Type
N/A