An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 29 Jan 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 29 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 28 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level. | |
Title | Incorrect Authorization in SimGear | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published: 2025-01-28T16:34:21.881Z
Updated: 2025-02-12T20:01:11.702Z
Reserved: 2025-01-28T13:04:32.712Z
Link: CVE-2025-0781

Updated: 2025-02-12T19:53:09.512Z

Status : Received
Published: 2025-01-28T17:15:25.947
Modified: 2025-01-29T22:15:30.187
Link: CVE-2025-0781

No data.