Описание
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Broken LinkThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- Broken LinkThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.4 (включая)
cpe:2.3:a:ktsuss_project:ktsuss:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.71594
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-273
Связанные уязвимости
CVSS3: 9.8
ubuntu
около 6 лет назад
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CVSS3: 9.8
debian
около 6 лет назад
ktsuss versions 1.4 and prior has the uid set to root and does not dro ...
CVSS3: 9.8
github
почти 4 года назад
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
EPSS
Процентиль: 99%
0.71594
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-273