CVE-2023-23558
Last modified
CVE-2023-23558 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eternal Terminal Project | Eternal Terminal | 6.2.1 |
References
- https://www.openwall.com/lists/oss-security/2023/02/16/1Mailing List, Patch, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1207126Exploit, Issue Tracking, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2023/02/16/1Mailing List, Patch, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1207126Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23558?
How severe is CVE-2023-23558?
How do I fix CVE-2023-23558?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23552On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, …7.5
- CVE-2023-23553 Control By Web X-400 devices are vulnerable to a cross-site…6.1
- CVE-2023-23554Uncontrolled search path element vulnerability exists in pg_…8.8
- CVE-2023-23555On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4…7.5
- CVE-2023-23556An error in BigInt conversion to Number in Hermes prior to c…9.8
- CVE-2023-23557An error in Hermes' algorithm for copying objects properties…9.8
- CVE-2023-23559In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in t…7.8
- CVE-2023-2356Relative Path Traversal in GitHub repository mlflow/mlflow p…7.5
- CVE-2023-23560In certain Lexmark products through 2023-01-12, SSRF can occ…9.8
- CVE-2023-23561Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorr…5.5
- CVE-2023-23562Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorr…4.3
- CVE-2023-23563An issue was discovered in Geomatika IsiGeo Web 6.0. It allo…6.5
Are you affected by CVE-2023-23558?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
