On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: rapid7
Published: 2022-07-29T17:00:46.360561Z
Updated: 2024-09-16T22:20:46.285Z
Reserved: 2022-07-11T00:00:00
Link: CVE-2022-35631
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-07-29T17:15:09.627
Modified: 2024-11-21T07:11:24.490
Link: CVE-2022-35631
Redhat
No data.