Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-3972

Опубликовано: 01 нояб. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).

Отчет

To exploit this CVE, in normal situations the attacker must have unprivileged access to the system before Insights is run for the first time on the system. Systems that are already running Insights on a regular frequent schedule should not consider themselves vulnerable. in other words, If Insights is registered before unprivileged users are given access, this specific problem doesn't appear to arise.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6insights-clientOut of support scope
Red Hat Enterprise Linux 7insights-clientFixedRHSA-2023:679508.11.2023
Red Hat Enterprise Linux 8insights-clientFixedRHSA-2023:628302.11.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutionsinsights-clientFixedRHSA-2023:681108.11.2023
Red Hat Enterprise Linux 8.2 Advanced Update Supportinsights-clientFixedRHSA-2023:626402.11.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update Serviceinsights-clientFixedRHSA-2023:626402.11.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionsinsights-clientFixedRHSA-2023:626402.11.2023
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportinsights-clientFixedRHSA-2023:679808.11.2023
Red Hat Enterprise Linux 8.4 Telecommunications Update Serviceinsights-clientFixedRHSA-2023:679808.11.2023
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionsinsights-clientFixedRHSA-2023:679808.11.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-61->CWE-379
https://bugzilla.redhat.com/show_bug.cgi?id=2227027insights-client: unsafe handling of temporary files and directories

EPSS

Процентиль: 1%
0.00008
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
больше 2 лет назад

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).

CVSS3: 7.8
github
больше 2 лет назад

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость оболочки клиентского API Insights-Client, связанная с созданием временных файлов с небезопасными разрешениями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.00008
Низкий

7.8 High

CVSS3