Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24612

Опубликовано: 24 авг. 2020
Источник: nvd
CVSS3: 6.7
CVSS3: 4.7
CVSS2: 1.9
EPSS Низкий

Описание

An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fedoraproject:selinux-policy:*:*:*:*:*:*:*:*
Версия от 3.14 (включая) до 2020-08-24 (включая)

EPSS

Процентиль: 16%
0.00051
Низкий

6.7 Medium

CVSS3

4.7 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 5 лет назад

An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

CVSS3: 4
redhat
больше 5 лет назад

An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

CVSS3: 6.7
debian
больше 5 лет назад

An issue was discovered in the selinux-policy (aka Reference Policy) p ...

github
больше 3 лет назад

An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

EPSS

Процентиль: 16%
0.00051
Низкий

6.7 Medium

CVSS3

4.7 Medium

CVSS3

1.9 Low

CVSS2

Дефекты

CWE-287