Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jeffrey

#17420of 53,630
15.4Total CVSS
Vulnerabilities · 2
High
2
PT-2023-27371
7.8
2023-08-13
Gnu · Gnu Inetutils · CVE-2023-40303
**Name of the Vulnerable Software and Affected Versions** GNU inetutils versions prior to 2.5 **Description** The issue allows privilege escalation due to unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process. **Recommendations** For GNU inetutils versions prior to 2.5, update to version 2.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the set*id() family functions in the affected services until a patch is available.
PT-2022-9683
7.6
2022-05-06
Unknown · Ingress-Nginx · CVE-2021-25746
**Name of the Vulnerable Software and Affected Versions** ingress-nginx (affected versions not specified) **Description** A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use `.metadata.annotations` in an Ingress object to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.