Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mmj-72wg-6gpv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

EPSS

Процентиль: 33%
0.00134
Низкий

7 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

CVSS3: 7
redhat
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

CVSS3: 4.4
nvd
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

CVSS3: 7
msrc
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission such as via sudo rules could use this flaw to escalate their privileges.

CVSS3: 4.4
debian
больше 5 лет назад

It was found that cifs-utils' mount.cifs was invoking a shell when req ...

EPSS

Процентиль: 33%
0.00134
Низкий

7 High

CVSS3

Дефекты

CWE-78