Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-1724

Опубликовано: 25 июл. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.3

Описание

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

2.63+24.10
esm-infra-legacy/xenial

released

2.61.4ubuntu0.16.04.1+esm1
esm-infra/bionic

released

2.61.4ubuntu0.18.04.1+esm1
esm-infra/focal

released

2.63+20.04ubuntu0.1
esm-infra/xenial

released

2.61.4ubuntu0.16.04.1+esm1
focal

released

2.63+20.04ubuntu0.1
jammy

released

2.63+22.04ubuntu0.1
mantic

ignored

end of life, was needed
noble

released

2.63+24.04ubuntu0.1

Показывать по

EPSS

Процентиль: 23%
0.00306
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
около 2 лет назад

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.

CVSS3: 6.3
nvd
около 2 лет назад

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatically added to the users PATH. An attacker who could convince a user to install a malicious snap which used the 'home' plug could use this vulnerability to install arbitrary scripts into the users PATH which may then be run by the user outside of the expected snap sandbox and hence allow them to escape confinement.

CVSS3: 6.3
debian
около 2 лет назад

In snapd versions prior to 2.62, when using AppArmor for enforcement o ...

CVSS3: 6.3
github
около 2 лет назад

snapd failed to restrict writes to the $HOME/bin path

EPSS

Процентиль: 23%
0.00306
Низкий

6.3 Medium

CVSS3