Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc87-5qgf-5qvj

Опубликовано: 12 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

EPSS

Процентиль: 14%
0.00233
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-284

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

CVSS3: 7.8
nvd
почти 4 года назад

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

CVSS3: 7.8
msrc
почти 4 года назад

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

EPSS

Процентиль: 14%
0.00233
Низкий

7.8 High

CVSS3

Дефекты

CWE-269
CWE-284