Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54p3-x8px-4jp3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

EPSS

Процентиль: 58%
0.00948
Низкий

7.8 High

CVSS3

Дефекты

CWE-266
CWE-269

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

CVSS3: 4.5
redhat
больше 7 лет назад

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

CVSS3: 7.8
nvd
больше 7 лет назад

It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the UID/GID will be recycled.

CVSS3: 7.8
msrc
почти 6 лет назад

Описание отсутствует

CVSS3: 7.8
debian
больше 7 лет назад

It was discovered that a systemd service that uses DynamicUser propert ...

EPSS

Процентиль: 58%
0.00948
Низкий

7.8 High

CVSS3

Дефекты

CWE-266
CWE-269