CVE Vulnerabilities

CVE-2017-2663

Privilege Context Switching Error

Published: Jul 27, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

It was found that subscription-managers DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain access to private information, or launch a privilege escalation attack.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Affected Software

NameVendorStart VersionEnd Version
Subscription-managerRedhat*1.19.4 (excluding)

Potential Mitigations

References