HIGH
Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell scripts" feature to insert "/Applications/Utilities/Terminal app/Contents/MacOS/Terminal" into the TCP data stream
Published Feb 25, 2019
7.5
HIGHCVSS 3.0
EPSS 0.78%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.