VYPR

Vagrant Vmware Fusion

Sign in to watch

by Hashicorp

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-7642Hig0.547.80.00Aug 2, 2017The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.
CVE-2017-15884Hig0.497.00.00Oct 31, 2017In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.