CVE Vulnerabilities

CVE-2020-36771

Published: Jan 22, 2024 | Modified: Mar 28, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

Affected Software

Name Vendor Start Version End Version
Cagefs Cloudlinux * 7.1.2-2 (excluding)

References