snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-04-24T20:02:32
Updated: 2024-08-04T22:55:40.662Z
Reserved: 2019-04-24T00:00:00
Link: CVE-2019-11502
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-04-24T21:29:00.727
Modified: 2019-05-02T13:35:31.683
Link: CVE-2019-11502
Redhat
No data.