{"id":"GHSA-w4f8-fxq2-j35v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-w4f8-fxq2-j35v","summary":"Possible privilege escalation via bash completion script","details":"The bash completion script for `fscrypt` through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the `fscrypt` bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.\n\nFor more details, see [CVE-2022-25328](https://www.cve.org/CVERecord?id=CVE-2022-25328).","published":"2022-03-01T21:04:57Z","modified":"2022-03-01T21:04:57Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/google/fscrypt","fixedVersion":"0.3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/google/fscrypt/security/advisories/GHSA-w4f8-fxq2-j35v"},{"type":"PACKAGE","url":"github.com/google/fscrypt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-03-01T21:04:57Z"}}