Описание
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | not-affected | RPM specfile issue |
| disco | ignored | end of life |
| eoan | ignored | end of life |
| esm-apps/focal | not-affected | RPM specfile issue |
| esm-infra-legacy/trusty | DNE | |
| focal | not-affected | RPM specfile issue |
| groovy | not-affected | RPM specfile issue |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
Показывать по
EPSS
7.2 High
CVSS2
7.8 High
CVSS3
Связанные уязвимости
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.
Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file ...
EPSS
7.2 High
CVSS2
7.8 High
CVSS3