Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23584
HistoryApr 10, 2020 - 12:31 a.m.

Privilege Escalation

2020-04-1000:31:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

40.7%

sudo is vulnerable to privilege escalation. The vulnerability exists as a flaw was discovered in a way sudo handled group specifications in β€œrun as” lists in the sudoers configuration file. If sudo configuration allowed a user to run commands as any user of some group and the user was also a member of that group, sudo incorrectly allowed them to run defined commands with the privileges of any system user. This gave the user unintended privileges.

References