pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Zenoss |
Zenoss |
2.5.3 (including) |
2.5.3 (including) |
References