VDB
CVE-2023-1521
CVE-2023-1521
PUBLISHED
CVSS 7.300000190734863 HIGH
sccache vulnerable to privilege escalation if server is run as root
EPSS 0.36% · 27.9th percentile
Risk Scores
CVSS 4.0
7.300000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
EPSS Score
0.36%
27.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | sccache | 0 |
| mozilla | sccache | 0 |
| mozilla | sccache | 0 |
| crates.io | sccache | 0 |
Timeline
- May 30, 2023 CVE Published
- Nov 26, 2024 CVE Updated
- Nov 27, 2024 EPSS Score
- Dec 16, 2024 EPSS Score
- Jan 2, 2025 EPSS Score
- Jan 20, 2025 EPSS Score
- Feb 24, 2025 EPSS Score
- Mar 14, 2025 EPSS Score
- Mar 27, 2025 EPSS Score
- Mar 28, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
References
- https://github.com/advisories/GHSA-x7fr-pg8f-93f5 advisory
- https://securitylab.github.com/advisories/GHSL-2023-046_ScCache exploit
- https://github.com/mozilla/sccache/security/advisories/GHSA-x7fr-pg8f-93f5 url
- https://nvd.nist.gov/vuln/detail/CVE-2023-1521 advisory
- https://github.com/mozilla/sccache package
- https://github.com/mozilla/sccache/releases/tag/v0.4.0 url