Loading HuntDB...

GHSA-hrr6-mvh4-hgmq

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details


The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer
system. This vulnerability stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to McFeeder server. An authenticated malicious client can
exploit this vulnerability by uploading a crafted ZIP archive via the
network to McFeeder’s service endpoint.

Related CVEs

Key Information

GHSA ID
GHSA-hrr6-mvh4-hgmq
Published
November 1, 2023 3:31 AM
Last Modified
November 8, 2023 9:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 28, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.