VulnerabilityModified
CVE-2022-45307
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
MEDIUM 4.3EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files located in that folder.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- chocolatey/chocolatey php
- Source
- cve@mitre.org
References
- https://github.com/ycdxsb/Vuln/blob/main/php-weak-permission-vuln/php-weak-permission-vuln.mdBroken Link, Third Party Advisory
- https://github.com/ycdxsb/Vuln/blob/main/php-weak-permission-vuln/php-weak-permission-vuln.mdBroken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.