CVE-2022-35631: Filesystem race on temporary files
Published Jul 29, 2022
·Updated
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.
Affected Software
3 affected components
Rapid7 Velociraptor<0.6.5-2
Apple macOS
Linux Linux kernel
Remediation
Event History
Jul 29, 2022
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-35631?
CVE-2022-35631 is a vulnerability in Velociraptor that allows for a symlink attack on MacOS and Linux.
2
How does CVE-2022-35631 work?
The vulnerability works by replacing a predictable file name with a symlink to another file, allowing the Velociraptor client to overwrite the other file.
3
Which software versions are affected by CVE-2022-35631?
Velociraptor versions up to and excluding 0.6.5-2 are affected by CVE-2022-35631.
4
What is the severity of CVE-2022-35631?
The severity of CVE-2022-35631 is medium, with a severity value of 5.5.
5
How was CVE-2022-35631 resolved?
CVE-2022-35631 was resolved in Velociraptor version 0.6.5-2.