漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Local Privilege Escalation Vulnerability in AWS Client VPN macOS Client
Vulnerability Description
Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient validation checks on the log destination directory during log rotation could allow a non-administrator user to create a symlink from a client log file to a privileged location. On log rotation, this could lead to code execution with root privileges if the user made crafted API calls which injected arbitrary code into the log file. We recommend users upgrade to AWS VPN Client for macOS 5.2.1 or the latest version.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
Amazon AWS VPN Client 安全漏洞
Vulnerability Description
Amazon AWS VPN Client是美国亚马逊(Amazon)公司的一种完全托管的远程访问 VPN 解决方案。 Amazon AWS VPN Client 1.3.2版本至5.2.0版本存在安全漏洞,该漏洞源于日志轮转期间对日志目标目录验证不足,可能导致权限提升和代码执行。
CVSS Information
N/A
Vulnerability Type
N/A