Privilege escalation through sudo misconfiguration
Vulnerability Description
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28139
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Daniel Hirschberger (SEC Consult Vulnerability Lab)
- Tobias Niemann (SEC Consult Vulnerability Lab)
References
More from Image Access GmbH
View All →Affected Vendor
Image Access GmbH
View all reports →