Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44749
HistoryDec 19, 2023 - 10:11 a.m.

Improper Access Control

2023-12-1910:11:02
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
improper access control
libslurm.so
vulnerability
restrictions
user-group list
unauthorized actions
extended group list
attacker
software

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

25.3%

libslurm.so is vulnerable to Improper Access Control. The vulnerability exists due to improper restrictions in the user-group list, which allow an attacker to perform unauthorized actions by modifying their extended group list.

CVSS3

8.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

25.3%