Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqqp-68qw-6v7r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).

EPSS

Процентиль: 85%
0.02628
Низкий

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).

EPSS

Процентиль: 85%
0.02628
Низкий

Дефекты

CWE-78