CVE-2023-45284
Incorrect detection of reserved device names on Windows in path/filepath
5.3
MEDIUM
CVSS 3.1
EPSS 0.90%
描述
On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.
如何修補 CVE-2023-45284
要修補 CVE-2023-45284,請將受影響套件升級到下列已修補版本。
- —升級至 1.20.11 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 1.20.11 或更新版本
CVE-2023-45284 正在被利用嗎?
低 — EPSS 為 0.9%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 1.20.11, >= 1.21.0-0, < 1.21.4
- from 0
- from 0
- from 0, < 1.20.11, >= 1.21.0-0, < 1.21.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |