CVE Feed

    Dashboard / CVE / CVE-2024-43791

    CVE-2024-43791

    RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 2017, and most production environments do not allow access for local users, so the chances of this being exploited are very low, given that the vast majority of users will have upgraded, and those that have not, if any, are not likely to be exposed.

    Published:Aug 23, 2024
    Last Modified:Sep 12, 2024
    EPS:Aug 23, 2024
    EPSS Score:0.00041
    CVSS Score:7.8

    Affected Products

    Vendor
    Steveklabnik
    Product
    Request Store

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High