CVE-2022-29526

Aliases:GHSA-p782-xgp4-8hr8BIT-golang-2022-29526GO-2022-0493
Modified
Published: 22 Jun 2022, 13:15
Last modified:03 Aug 2024, 06:26

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.18% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Jun 2022, 13:15
Published
Vulnerability first disclosed
03 Aug 2024, 06:26
Last Modified
Vulnerability information updated

Description

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.18% Percentile: 40%

Techniques & Countermeasures

  • CWE-269Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Systems

  • fedoraprojectfedora

    35 | 36

  • golanggo

    < 1.17.10 | ≥ 1.18.0, < 1.18.2

  • golang.org/xsys

    < 0.0.0-20220412211240-33da011f77ad

  • Gostdlib

    ≥ 1.18.0-0, < 1.18.2

  • netappbeegfs_csi_driver

    na

References (20)