First published: Fri Jul 29 2022(Updated: )
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 Velociraptor | <0.6.5-2 | |
Apple macOS | ||
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35631 is a vulnerability in Velociraptor that allows for a symlink attack on MacOS and Linux.
The vulnerability works by replacing a predictable file name with a symlink to another file, allowing the Velociraptor client to overwrite the other file.
Velociraptor versions up to and excluding 0.6.5-2 are affected by CVE-2022-35631.
The severity of CVE-2022-35631 is medium, with a severity value of 5.5.
CVE-2022-35631 was resolved in Velociraptor version 0.6.5-2.