ZeroHour

CVE-2020-36771

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p40
Published
()
Modified
Description

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

Vendors
cloudlinux
Products
cagefs
Weakness
CWE-214, CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.