{"id":"GHSA-w4f8-fxq2-j35v","summary":"Possible privilege escalation via bash completion script","details":"The bash completion script for `fscrypt` through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the `fscrypt` bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.\n\nFor more details, see [CVE-2022-25328](https://www.cve.org/CVERecord?id=CVE-2022-25328).","modified":"2022-03-01T21:04:57Z","published":"2022-03-01T21:04:57Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-03-01T21:04:57Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/google/fscrypt/security/advisories/GHSA-w4f8-fxq2-j35v"},{"type":"PACKAGE","url":"github.com/google/fscrypt"}],"affected":[{"package":{"name":"github.com/google/fscrypt","ecosystem":"Go","purl":"pkg:golang/github.com/google/fscrypt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-w4f8-fxq2-j35v/GHSA-w4f8-fxq2-j35v.json"}}],"schema_version":"1.9.0"}