Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-22029

Опубликовано: 14 фев. 2024
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

A flaw was found in the Tomcat package of OpenSUSE and derived distributions. This issue occurs due to incorrect permissions and a race condition in the %post section of the Tomcat RPM package, resulting in local privilege escalation when the Tomcat package is re-installed.

Отчет

This flaw is specific to OpenSUSE and derived distributions. Therefore, Red Hat products are not affected by this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatNot affected
Red Hat Enterprise Linux 6tomcat6Not affected
Red Hat Enterprise Linux 7tomcatNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineNot affected
Red Hat Enterprise Linux 8tomcatNot affected
Red Hat Enterprise Linux 9pki-servlet-engineNot affected
Red Hat Enterprise Linux 9tomcatNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2271114tomcat: Escalation to root from tomcat user via %post script

EPSS

Процентиль: 2%
0.00014
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 1 года назад

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVSS3: 7.8
nvd
больше 1 года назад

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVSS3: 7.8
debian
больше 1 года назад

Insecure permissions in the packaging of tomcat allow local users that ...

suse-cvrf
почти 2 года назад

Security update for tomcat10

CVSS3: 7.8
github
больше 1 года назад

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

EPSS

Процентиль: 2%
0.00014
Низкий

7 High

CVSS3