Description
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2640 | HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0. |
Github GHSA |
GHSA-47xw-vw6m-w9fq | HashiCorp Vagrant Insecure Operation on Windows Junction / Mount Point vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-09-09T17:58:26.595Z
Reserved: 2023-10-27T19:52:44.844Z
Link: CVE-2023-5834
Updated: 2024-08-02T08:14:24.694Z
Status : Modified
Published: 2023-10-27T22:15:09.163
Modified: 2024-11-21T08:42:35.567
Link: CVE-2023-5834
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA