Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq7j-25x9-p735

Опубликовано: 18 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

EPSS

Процентиль: 86%
0.02836
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-271

Связанные уязвимости

CVSS3: 7.8
nvd
больше 3 лет назад

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary commands as 'root'.

EPSS

Процентиль: 86%
0.02836
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-271