On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Velociraptor | Rapid7 | * | 0.6.5-2 (excluding) |