Description
The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Users should update to version 6.0.3 or later of the Metasploit Framework.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28503 | The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host. |
References
| Link | Providers |
|---|---|
| https://github.com/rapid7/metasploit-framework/issues/14008 |
|
History
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T23:35:28.125Z
Reserved: 2020-01-21T00:00:00.000Z
Link: CVE-2020-7376
No data.
Status : Modified
Published: 2020-08-24T19:15:10.713
Modified: 2024-11-21T05:37:07.917
Link: CVE-2020-7376
No data.
OpenCVE Enrichment
No data.
EUVD