HIGH
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312
Published Nov 18, 2017
7.8
HIGHCVSS 3.0
EPSS 0.31%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.