Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-17T16:58:56
Updated: 2024-08-04T15:33:05.701Z
Reserved: 2020-09-14T00:00:00
Link: CVE-2020-25490
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-17T17:15:16.303
Modified: 2024-11-21T05:18:02.920
Link: CVE-2020-25490
Redhat
No data.