Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Insecure handling of file paths allows multiple local attacks
Vulnerability Description
Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
ISC Kea 安全漏洞
Vulnerability Description
ISC Kea是ISC组织的一个现代开源 DHCPv4 和 DHCPv6 服务器。 ISC Kea 2.4.0至2.4.1版本、2.6.0至2.6.2版本和2.7.0至2.7.8版本存在安全漏洞,该漏洞源于配置和API指令可覆盖任意文件,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A