漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ClearanceKit has a policy bypass via dual-path Endpoint Security events checking only source path
Vulnerability Description
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta-1f46165, ClearanceKit's Endpoint Security event handler only checked the source path of dual-path file operations against File Access Authorization (FAA) rules and App Jail policies. The destination path was ignored entirely. This allowed any local process to bypass file-access protection by using rename, link, copyfile, exchangedata, or clone operations to place or replace files inside protected directories. This vulnerability is fixed in 5.0.4-beta-1f46165.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
ClearanceKit 安全漏洞
Vulnerability Description
ClearanceKit是Craig J. Bass个人开发者的一个macOS文件系统访问控制工具。 ClearanceKit 5.0.4-beta-1f46165之前版本存在安全漏洞,该漏洞源于端点安全事件处理程序仅检查双路径文件操作的源路径,而完全忽略目标路径,可能导致任何本地进程通过重命名、链接、复制文件等操作绕过文件访问保护。
CVSS Information
N/A
Vulnerability Type
N/A