Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11075

Опубликовано: 19 нояб. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-250

Связанные уязвимости

CVSS3: 8.8
github
около 1 года назад

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVSS3: 8.8
fstec
около 1 года назад

Уязвимость образа Docker средства регистрации посылок и отправлений Incoming Goods Suite, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 25%
0.00088
Низкий

8.8 High

CVSS3

Дефекты

CWE-250