Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6635-xfqx-gr6m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.

There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.

EPSS

Процентиль: 18%
0.00058
Низкий

Связанные уязвимости

CVSS3: 6.4
nvd
больше 5 лет назад

There is no mechanism in place to prevent a bad operator to boot from a live OS image, this can lead to extraction of sensible files (such as the shadow file) or privilege escalation by manually adding a new user with sudo privileges on the machine.

EPSS

Процентиль: 18%
0.00058
Низкий