CVE Vulnerabilities

CVE-2020-14318

Incorrect Privilege Assignment

Published: Dec 03, 2020 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
SambaSamba3.6.0 (including)4.11.15 (excluding)
SambaSamba4.12.0 (including)4.12.9 (excluding)
SambaSamba4.13.0 (including)4.13.1 (excluding)
Red Hat Enterprise Linux 7RedHatsamba-0:4.10.16-9.el7_9*
Red Hat Enterprise Linux 8RedHatopenchange-0:2.3-27.el8*
Red Hat Enterprise Linux 8RedHatsamba-0:4.13.3-3.el8*
Red Hat Enterprise Linux 8RedHatopenchange-0:2.3-27.el8*
Red Hat Enterprise Linux 8RedHatsamba-0:4.13.3-3.el8*
Red Hat Gluster Storage 3.5 for RHEL 7RedHatsamba-0:4.11.6-112.el7rhgs*
Red Hat Gluster Storage 3.5 for RHEL 8RedHatsamba-0:4.13.7-101.el8rhgs*
SambaUbuntubionic*
SambaUbuntudevel*
SambaUbuntuesm-infra-legacy/trusty*
SambaUbuntuesm-infra/bionic*
SambaUbuntuesm-infra/focal*
SambaUbuntuesm-infra/xenial*
SambaUbuntufocal*
SambaUbuntugroovy*
SambaUbuntuhirsute*
SambaUbuntuprecise/esm*
SambaUbuntutrusty*
SambaUbuntutrusty/esm*
SambaUbuntuupstream*
SambaUbuntuxenial*

Potential Mitigations

References