Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-54445

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is not ideal because attackers know that almost all vantage6 servers have a user with username `root` that probably has admin rights, and the initial password is very weak and it is possible that administrators forget to reset it. Version 5.0.0 fixes the issue. As a workaround, it is possible to delete the `root` user after it h

PUBLISHED
Vendor
vantage6
Product
vantage6
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54443

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.

PUBLISHED
Vendor
lissy93
Product
dashy
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5444

A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image embedded in a DICOM file, image dimensions are multiplied using 32-bit unsigned arithmetic. Specially chosen values can cause an integer overflow during buffer size calculation, resulting in the allocation of a small buffer followed by a much larger write operation during pixel processing.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
HIGH
Conflicts
0

CVE-2026-54433

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
HIGH
Conflicts
0

CVE-2026-54432

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

PUBLISHED
Vendor
Roundcube
Product
Webmail
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54431

In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header. This issue was fixed in version 2.3.0

PUBLISHED
Vendor
OpenIDC
Product
liboauth2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54430

liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If signer matches the configured ARN, kid is appended to alb_base_url without URL encoding or path sanitization, and the HTTP GET is issued before signature verification. This allows an attacker to force the server to send a GET request to an attacker-chosen internal path. This issue was fixed in version 2.3.0

PUBLISHED
Vendor
OpenIDC
Product
liboauth2
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5443

A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation uses 32-bit multiplication for width and height calculations. If these values overflow, the validation check incorrectly succeeds, allowing the decoder to read and write to memory beyond allocated buffers.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54429

A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handle high-volume multicast network traffic, which can exhaust available memory resources in the affected application. This could allow an unauthenticated attacker on the local network segment to cause a denial-of-service condition of the affected application. The affected application becomes inaccessible and requires a manual restart; no project data is lost. Successful exploitati

PUBLISHED
Vendor
Siemens
Product
SIMATIC S7-PLCSIM Advanced
Provider severity
HIGH, MEDIUM
Conflicts
1

CVE-2026-54428

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HttpComponents Core
Provider severity
HIGH
Conflicts
1

CVE-2026-54424

An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable.

PUBLISHED
Vendor
Unity
Product
Parsec
Provider severity
HIGH
Conflicts
0

CVE-2026-54423

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.

PUBLISHED
Vendor
OpenStack
Product
Ironic
Provider severity
HIGH
Conflicts
0

CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

PUBLISHED
Vendor
OpenStack
Product
Ironic Python Agent
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54421

In OpenStack Ironic before 37.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security issue.

PUBLISHED
Vendor
OpenStack
Product
Ironic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54420

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026.

PUBLISHEDCISA KEV
Vendor
LiteSpeed Technologies
Product
cPanel Plugin
Provider severity
HIGH
Conflicts
0

CVE-2026-5442

A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
CRITICAL
Conflicts
0

CVE-2026-54419

claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The application has no authentication mechanism and passes user-supplied HTTP parameters directly into deprecated mysql_query() calls via string concatenation, without sanitization, escaping, or parameterization. Affected sinks include rooms.php (DELETE FROM Rooms WHERE ID = $_GET['ID'], un

PUBLISHED
Vendor
claudiopizzillo
Product
PIAF-HMS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54417

An integer overflow in the mtar_next() function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause a denial of service (uncontrolled CPU consumption / infinite loop) via a crafted tar archive. mtar_next() computes the offset to the next record as round_up(h.size, 512) + sizeof(mtar_raw_header_t) using 32-bit arithmetic. When the header size field is a multiple of 512 in the range 0xFFFFFC01-0xFFFFFE00 (e.g. 0xFFFFFE00), the addition wraps to 0, so mtar_next() seeks to the

PUBLISHED
Vendor
rxi
Product
microtar
Provider severity
HIGH
Conflicts
2

CVE-2026-54415

Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all platforms allows an authenticated attacker with the admin.access permission to create AzLink server tokens and take over non-admin user accounts by changing their passwords and email addresses via crafted HTTP requests to /admin/servers/create and the AzLink API endpoints (/api/azlink/password, /api/azlink/email, /api/azlink/user/{id}).

PUBLISHED
Vendor
Azuriom
Product
Azuriom CMS
Provider severity
HIGH
Conflicts
2

CVE-2026-54414

FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %). The raw filename is then passed to UploadModel::handleUpload, where it is reconstructed as trim(urldecode(basename($fileName))), re-intro

PUBLISHED
Vendor
error311
Product
FileRise
Provider severity
CRITICAL
Conflicts
2

CVE-2026-54413

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27 SecurityAccess request that follows any earlier well-formed 0x27 message. The handler reads the SecurityAccess subFunction from recv_buf[1] without first checking that recv_len is at least 2,

PUBLISHED
Vendor
driftregion
Product
iso14229
Provider severity
HIGH
Conflicts
2

CVE-2026-54412

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticated attacker controlling an MQTT broker - or able to inject MQTT traffic into an unencrypted session - to crash a subscribed MQTT-C client and potentially disclose adjacent heap memory by sending a single crafted PUBLISH packet. The function validates only that the fixed-header remaining_length is at l

PUBLISHED
Vendor
LiamBindle
Product
MQTT-C
Provider severity
HIGH
Conflicts
2

CVE-2026-54411

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so t

PUBLISHED
Vendor
Linux-PAM
Product
Linux-PAM
Provider severity
MEDIUM
Conflicts
1

CVE-2026-54410

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of the 260-byte receive buffer by sending a crafted MBAP frame whose Length field is set to 255. The overflow corrupts the adjacent buffer-index field of the nanoMODBUS state structure, resulting in denial of service through invalid memory accesses and, on bare-metal and RTOS ta

PUBLISHED
Vendor
debevv
Product
nanoMODBUS
Provider severity
HIGH
Conflicts
2

CVE-2026-5441

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
HIGH
Conflicts
0

CVE-2026-54409

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi Protect Application
Provider severity
HIGH
Conflicts
0

CVE-2026-54408

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi Protect Application
Provider severity
HIGH
Conflicts
0

CVE-2026-54407

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi Protect Application
Provider severity
HIGH
Conflicts
0

CVE-2026-54406

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi Network Application
Provider severity
HIGH
Conflicts
0

CVE-2026-54405

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi Network Application
Provider severity
HIGH
Conflicts
0

CVE-2026-54404

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
Dream Machines, Dream Routers, Express 7, Enterprise Video Recorders, Cloud Keys, Enterprise Firewall Core, UniFi OS Server, Dream Wall, Network Video Recorders, Network Attached Storage, Cloud Gateways, Enterprise Fortress Gateway
Provider severity
HIGH
Conflicts
1

CVE-2026-54403

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
UniFi OS Server, Dream Routers, Enterprise Firewall Core, Enterprise Fortress Gateway, Network Video Recorders, Cloud Keys, Dream Wall, Cloud Gateways, Dream Machines, Enterprise Video Recorders, Express 7, Network Attached Storage
Provider severity
HIGH
Conflicts
1

CVE-2026-54402

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
Cloud Gateways, Dream Machines, Network Video Recorders, Dream Wall, Enterprise Firewall Core, Enterprise Fortress Gateway, Express 7, Dream Routers, UniFi OS Server, Enterprise Video Recorders, Cloud Keys, Network Attached Storage
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54401

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.

PUBLISHED
Vendor
Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc, Ubiquiti Inc
Product
Dream Routers, Enterprise Firewall Core, Enterprise Video Recorders, Cloud Keys, Dream Wall, Dream Machines, Enterprise Fortress Gateway, UniFi OS Server, Network Attached Storage, Cloud Gateways, Network Video Recorders, Express 7
Provider severity
HIGH
Conflicts
1

CVE-2026-54400

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

PUBLISHED
Vendor
Ubiquiti Inc
Product
UniFi Access Application
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5440

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely large `Content-Length` value can trigger excessive memory allocation and server termination, even without sending a request body.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
HIGH
Conflicts
0

CVE-2026-54399

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache HttpComponents Core
Provider severity
HIGH
Conflicts
0

CVE-2026-54398

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group validation was performed against the wrong request data structure after object fields had been merged to the top level, causing the check to be bypassed. In addition, attributes embedded in objects were not

PUBLISHED
Vendor
misp
Product
misp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54397

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form data and set an event’s sharing_group_id to a sharing group they were not authorized to use. When distribution was set to sharing group distribution, the non-REST save path accepted the submitted sharing_group_id without performing the same sharing group authorization check enforced by the REST edit path. An attacker could exploit this by tampering wit

PUBLISHED
Vendor
misp
Product
misp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54396

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit request, the user dropdown was populated using the attacker-controlled AuthKey.user_id value from the submitted request data. An authenticated user with permission to edit an AuthKey could submit arbitrary user IDs and observe the returned dropdown data, allowing enumeration of user email addresses. The issue is fixed by deriving the dropdown user from the

PUBLISHED
Vendor
misp
Product
misp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54395

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScript handler using HTML escaping inside a single-quoted JavaScript string. Because browsers HTML-decode attribute values before JavaScript parsing, a crafted searcheventinfo value can restore encoded quote characters and break out of the JavaScript string. An attacker could craft a malicious URL that, when opened by a victim using the UiBeta event inde

PUBLISHED
Vendor
misp
Product
misp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54394

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using organisation-controlled fields such as id, name, and uuid without ensuring that the resolved file remains inside the intended APP/files/img/orgs/ directory. An attacker able to influence an organisation field, for example the organisation name, could use path traversal sequences to cause MISP to return arbitrary readable .png or .svg files from outsid

PUBLISHED
Vendor
misp
Product
misp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54393

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-controlled path value through setSettingInternal(), bypassing the normal setSetting() validation logic, including validate_homepage, which requires homepage paths to start with /. As a result, an authenticated user could store an arbitrary homepage value, including an XSS payload. The stored value was later rendered in app/View/News/index.ctp as the href

PUBLISHED
Vendor
misp
Product
misp
Provider severity
MEDIUM
Conflicts
0

CVE-2026-54390

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_contents to write a webshel

PUBLISHED
Vendor
JTL Software
Product
JTL Shop
Provider severity
CRITICAL
Conflicts
1

CVE-2026-5439

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
HIGH
Conflicts
0

CVE-2026-54388

Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.

PUBLISHED
Vendor
tinyproxy
Product
tinyproxy
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54387

Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.

PUBLISHED
Vendor
tinyproxy
Product
tinyproxy
Provider severity
CRITICAL
Conflicts
1

CVE-2026-54386

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Attackers can craft a malicious link with a payload beginning with __new__ to bypass the 404 check and inject JavaScript into the page, which executes without Content-Security-Policy restrictions in the o

PUBLISHED
Vendor
marimo-team
Product
marimo
Provider severity
MEDIUM
Conflicts
1

CVE-2026-5438

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on attacker-controlled compression metadata. A specially crafted gzip payload can trigger excessive memory allocation and exhaust system memory.

PUBLISHED
Vendor
Orthanc
Product
DICOM Server
Provider severity
HIGH
Conflicts
0

CVE-2026-54371

A flaw was found in the `attr` package. This vulnerability allows a local attacker to perform a symlink traversal attack by replacing a pathname component with a symbolic link - either during directory hierarchy traversal by `getfattr` or during backup restoration by `setfattr`, which reads and resolves full pathnames from backup files. In both cases, when these utilities are executed by a privileged process over a path controlled by the attacker, this can lead to local privilege escalation.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, attr project
Product
Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Hardened Images, attr
Provider severity
HIGH, MEDIUM
Conflicts
2