CVE-2019-15119

lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:*

History

17 Apr 2025, 14:56

Type Values Removed Values Added
CPE cpe:2.3:a:nps_project:nps:*:*:*:*:*:*:*:* cpe:2.3:a:ehang-io:nps:*:*:*:*:*:*:*:*
First Time Ehang-io
Ehang-io nps

Information

Published : 2019-08-16 15:15

Updated : 2025-04-17 14:56


NVD link : CVE-2019-15119

Mitre link : CVE-2019-15119

CVE.ORG link : CVE-2019-15119


JSON object : View

Products Affected

ehang-io

  • nps
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource