Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-16933

Опубликовано: 24 нояб. 2017
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.8.0 (включая)

EPSS

Процентиль: 8%
0.0003
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7
ubuntu
около 8 лет назад

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

CVSS3: 7
debian
около 8 лет назад

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown ca ...

CVSS3: 7
github
больше 3 лет назад

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

EPSS

Процентиль: 8%
0.0003
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-732