CVE-2019-12162
Summary
| CVE | CVE-2019-12162 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-23 15:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which could lead to code execution or local privilege escalation by replacing the original update.exe. |
Risk And Classification
Problem Types: CWE-494
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Upwork | Time Tracker | 5.2.2.716 | All | All | All |
| Application | Upwork | Time Tracker | 5.2.2.716 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-12162 | Upwork Time Tracker Update SHA256 access control | MISC | vuldb.com | Third Party Advisory |
| Apps – Upwork Help | MISC | support.upwork.com | Product, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.