Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16882

Опубликовано: 18 нояб. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin/log2ido.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*
Версия до 1.14.0 (включая)

EPSS

Процентиль: 13%
0.00042
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin/log2ido.

CVSS3: 7.8
debian
около 8 лет назад

Icinga Core through 1.14.0 initially executes bin/icinga as root but s ...

CVSS3: 7.8
github
больше 3 лет назад

Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin/log2ido.

EPSS

Процентиль: 13%
0.00042
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-732