We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-34528



Assignermitre
Reserved2024-05-05
Published2024-05-05
Updated2024-11-01

Description

WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.

References

https://github.com/WordOps/WordOps/issues/611

https://github.com/WordOps/WordOps/blob/ecf20192c7853925e2cb3f8c8378cd0d86ca0d62/wo/cli/plugins/stack_pref.py#L77

cve.org CVE-2024-34528

nvd.nist.gov CVE-2024-34528

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-34528
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.