Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python313Packages.pebble

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2024-3250
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
created 6 months ago
It was discovered that Canonical's Pebble service manager read-file API …

It was discovered that Canonical's Pebble service manager read-file API and the associated pebble pull command, before v1.10.2, allowed unprivileged local users to read files with root-equivalent permissions when Pebble was running as root. Fixes are also available as backports to v1.1.1, v1.4.2, and v1.7.4.

Affected products

pebble
  • <v1.10.2

Matching in nixpkgs

pkgs.pebble

Small RFC 8555 ACME test server

  • nixos-unstable -

Package maintainers