CVE-2024-34528 – WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because …

Vuln ID: CVE-2024-34528

Published:  2024-05-06  00:15:10.263

Description: WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.

Base Score:

Vector:

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):