Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:10936
HistoryJan 15, 2019 - 8:54 a.m.

Authorization Bypass

2019-01-1508:54:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.0004 Low

EPSS

Percentile

5.1%

sudo is vulnerable to authorization bypass. This is due to improper handling of multiple IP networks listed in user specification configuration directives. A local user who is authorized to run commands with sudo on specific hosts is able to bypass restrictions and run commands on hosts that are not matched by any of the network specifications.