Shortened for this page: results: 3 of 25 shown; results[].references: first 10 items
{
"page": 1,
"page_size": 25,
"result_count": 1733,
"results": [
{
"id": "CVE-2024-28189",
"source_identifier": "user@github.com",
"published": "2024-04-18T15:15:29Z",
"last_modified": "2026-06-17T07:21:10Z",
"status": "Deferred",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on arbitrary files outside of the sandbox. This vulnerability is not impactful on it's own, but it can be used to bypass the patch for CVE-2024-28185 and obtain a complete sandbox escape. This vulnerability is fixed in 1.13.1."
},
{
"lang": "es",
"value": "Judge0 es un sistema de ejecución de código en línea de código abierto. La aplicación utiliza el comando chown de UNIX en un archivo que no es de confianza dentro del entorno limitado. Un atacante puede abusar de esto creando un enlace simbólico (enlace simbólico) a un archivo fuera del entorno sandbox, lo que le permite ejecutar chown en archivos arbitrarios fuera del entorno sandbox. Esta vulnerabilidad no tiene un impacto por sí sola, pero se puede utilizar para omitir el parche CVE-2024-28185 y obtener un escape completo de la zona de pruebas. Esta vulnerabilidad se solucionó en 1.13.1."
}
],
"references": [
{
"url": "https://github.com/judge0/judge0/blob/v1.13.0/app/jobs/isolate_job.rb#L232",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/commit/f3b8547b3b67863e4ea0ded3adcb963add56addd",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/security/advisories/GHSA-3xpw-36v7-2cmg",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/security/advisories/GHSA-h9g2-45c8-89cf",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/blob/v1.13.0/app/jobs/isolate_job.rb#L232",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/commit/f3b8547b3b67863e4ea0ded3adcb963add56addd",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/security/advisories/GHSA-3xpw-36v7-2cmg",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/security/advisories/GHSA-h9g2-45c8-89cf",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": [
{
"source": "user@github.com",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH",
"base_score": 10.0,
"base_severity": "CRITICAL",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.9,
"impact_score": 6.0
}
],
"cvss_metric_v30": null,
"cvss_metric_v2": null
},
"weaknesses": [
{
"source": "user@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-59"
},
{
"lang": "en",
"value": "CWE-61"
}
]
}
],
"configurations": null,
"vendor_comments": null,
"enrichment": {
"cpe": null,
"cwe": [
{
"id": 59,
"owasptop10_2021": "A01 Broken Access Control",
"name": "Improper Link Resolution Before File Access ('Link Following')",
"description": "The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.",
"capec_id": [
17,
35,
76,
132
],
"scope": [
"Access Control",
"Confidentiality",
"Integrity",
"Other"
],
"impact": [
"Bypass Protection Mechanism",
"Execute Unauthorized Code or Commands",
"Modify Files or Directories",
"Read Files or Directories"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
},
{
"id": 61,
"owasptop10_2021": null,
"name": "UNIX Symbolic Link (Symlink) Following",
"description": "The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.",
"capec_id": [
27
],
"scope": [
"Confidentiality",
"Integrity"
],
"impact": [
"Modify Files or Directories",
"Read Files or Directories"
],
"detection_method": [
"Automated Static Analysis"
]
}
],
"epss_score": {
"epss": 0.07211,
"percentile": 0.94042,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"3.1"
],
"source": "user@github.com",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": "NONE",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": "HIGH",
"vulnerable_system_integrity": "HIGH",
"vulnerable_system_availability": "HIGH",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "CRITICAL"
}
}
}
},
{
"id": "CVE-2024-28185",
"source_identifier": "user@github.com",
"published": "2024-04-18T15:15:29Z",
"last_modified": "2026-06-17T07:21:09Z",
"status": "Deferred",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code execution outside of the sandbox. When executing a submission, Judge0 writes a `run_script` to the sandbox directory. The security issue is that an attacker can create a symbolic link (symlink) at the path `run_script` before this code is executed, resulting in the `f.write` writing to an arbitrary file on the unsandboxed system. An attacker can leverage this vulnerability to overwrite scripts on the system and gain code execution outside of the sandbox.\n"
},
{
"lang": "es",
"value": "Judge0 es un sistema de ejecución de código en línea de código abierto. La aplicación no tiene en cuenta los enlaces simbólicos colocados dentro del directorio de la zona de pruebas, que un atacante puede aprovechar para escribir en archivos arbitrarios y obtener la ejecución de código fuera de la zona de pruebas. Al ejecutar un envío, Judge0 escribe un `run_script` en el directorio sandbox. El problema de seguridad es que un atacante puede crear un enlace simbólico (enlace simbólico) en la ruta `run_script` antes de que se ejecute este código, lo que da como resultado que `f.write` escriba en un archivo arbitrario en el sistema sin espacio aislado. Un atacante puede aprovechar esta vulnerabilidad para sobrescribir scripts en el sistema y obtener la ejecución del código fuera del entorno limitado."
}
],
"references": [
{
"url": "https://github.com/judge0/judge0/blob/v1.13.0/app/jobs/isolate_job.rb#L197-L201",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/commit/846d5839026161bb299b7a35fd3b2afb107992fc",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/security/advisories/GHSA-h9g2-45c8-89cf",
"source": "user@github.com",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/blob/v1.13.0/app/jobs/isolate_job.rb#L197-L201",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/commit/846d5839026161bb299b7a35fd3b2afb107992fc",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "https://github.com/judge0/judge0/security/advisories/GHSA-h9g2-45c8-89cf",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": [
{
"source": "user@github.com",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH",
"base_score": 10.0,
"base_severity": "CRITICAL",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.9,
"impact_score": 6.0
}
],
"cvss_metric_v30": null,
"cvss_metric_v2": null
},
"weaknesses": [
{
"source": "user@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-59"
},
{
"lang": "en",
"value": "CWE-61"
}
]
}
],
"configurations": null,
"vendor_comments": null,
"enrichment": {
"cpe": null,
"cwe": [
{
"id": 59,
"owasptop10_2021": "A01 Broken Access Control",
"name": "Improper Link Resolution Before File Access ('Link Following')",
"description": "The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.",
"capec_id": [
17,
35,
76,
132
],
"scope": [
"Access Control",
"Confidentiality",
"Integrity",
"Other"
],
"impact": [
"Bypass Protection Mechanism",
"Execute Unauthorized Code or Commands",
"Modify Files or Directories",
"Read Files or Directories"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
},
{
"id": 61,
"owasptop10_2021": null,
"name": "UNIX Symbolic Link (Symlink) Following",
"description": "The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.",
"capec_id": [
27
],
"scope": [
"Confidentiality",
"Integrity"
],
"impact": [
"Modify Files or Directories",
"Read Files or Directories"
],
"detection_method": [
"Automated Static Analysis"
]
}
],
"epss_score": {
"epss": 0.07057,
"percentile": 0.93921,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"3.1"
],
"source": "user@github.com",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": "NONE",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": "HIGH",
"vulnerable_system_integrity": "HIGH",
"vulnerable_system_availability": "HIGH",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "CRITICAL"
}
}
}
},
{
"id": "CVE-2014-4480",
"source_identifier": "user@apple.com",
"published": "2015-01-30T11:59:12Z",
"last_modified": "2026-06-17T00:10:06Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in afc in AppleFileConduit in Apple iOS before 8.1.3 and Apple TV before 7.0.3 allows attackers to access unintended filesystem locations by creating a symlink."
},
{
"lang": "es",
"value": "Salto de directorio en afc en AppleFileConduit en Apple iOS anterior a 8.1.3 y Apple TV anterior a 7.0.permite a atacantes remotos acceder a localizaciones del sistema de ficheros mediante la creación de un enlace simbólico."
}
],
"references": [
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html",
"source": "user@apple.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html",
"source": "user@apple.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.apple.com/HT204245",
"source": "user@apple.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.apple.com/HT204246",
"source": "user@apple.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/72334",
"source": "user@apple.com",
"tags": null
},
{
"url": "http://www.securitytracker.com/id/1031652",
"source": "user@apple.com",
"tags": null
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00000.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://lists.apple.com/archives/security-announce/2015/Jan/msg00001.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.apple.com/HT204245",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.apple.com/HT204246",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Vendor Advisory"
]
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"match_criteria_id": "31944D25-25B6-4EA4-92B0-6B03921E0CCE",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "8.1.2",
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"match_criteria_id": "1C32F3FB-EBDF-4A80-B7D9-42EDEF5DC6F4",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "7.0.1",
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": null,
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vendor": "apple",
"product": "iphone_os",
"product_type": "o",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "8.1.2",
"version_end_excluding": null,
"affected_versions_first": "1.0.0",
"affected_versions_last": "8.1.2"
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"vendor": "apple",
"product": "tvos",
"product_type": "o",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "7.0.1",
"version_end_excluding": null,
"affected_versions_first": "1.0.0",
"affected_versions_last": "7.0.1"
}
],
"cwe": [
{
"id": 59,
"owasptop10_2021": "A01 Broken Access Control",
"name": "Improper Link Resolution Before File Access ('Link Following')",
"description": "The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.",
"capec_id": [
17,
35,
76,
132
],
"scope": [
"Access Control",
"Confidentiality",
"Integrity",
"Other"
],
"impact": [
"Bypass Protection Mechanism",
"Execute Unauthorized Code or Commands",
"Modify Files or Directories",
"Read Files or Directories"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
}
],
"epss_score": {
"epss": 0.02799,
"percentile": 0.85863,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
}
]
}