Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23969
HistoryApr 10, 2020 - 12:42 a.m.

Privilege Escalation

2020-04-1000:42:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0

Percentile

10.1%

The sudo (superuser do) is vulnerable to Privilege Escalation. The sudo utility did not properly initialize supplementary groups when the “runas_default” option (in the sudoers file) was used. If a local user were authorized by the sudoers file to perform their sudo commands under the account specified with “runas_default”, they would receive the root user’s supplementary groups instead of those of the intended target user, giving them unintended privileges.

References