HIGH
The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate
Published May 2, 2019
7.0
HIGHCVSS 3.0
EPSS 0.23%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.