SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0167

The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other…

MEDIUM 4.6EPSS 0.73%

Does this matter?

Lower severity and a low EPSS score (0.73%). Track it; it rarely justifies an emergency change on its own.

Description

The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
0.73% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-59
Affected
gforge/gforge
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.