Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8jjp-3pj6-xx8j

Опубликовано: 17 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

EPSS

Процентиль: 90%
0.05122
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость функции zmslapd корпоративной системы управления электронной почтой Zimbra Collaboration Suite (ZCS), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05122
Низкий

7.8 High

CVSS3