35
CVE-2019-14287
PoC ×2—CVSS 3.1
8.8 high
EPSS
64%p99
Published
()
Modified
Description
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.
- Vendors
- sudo projectfedoraprojectdebianopensusecanonicalnetappredhat
- Products
- sudo, fedora, debian linux, leap, ubuntu linux, element software management node, openshift container platform, virtualization, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server
- Weakness
- CWE-755
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H