Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Robert Ancell

#35507of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2018-5624
7.5
2018-02-02
Canonical · Snapd · CVE-2017-14178
Name of the Vulnerable Software and Affected Versions: snapd versions 2.27 through 2.29.2 Description: The issue allows unprivileged, unauthenticated users to bypass systemd-journald's access restrictions by making the 'snap logs' command call journalctl without match arguments. Recommendations: For snapd versions 2.27 through 2.29.2, consider restricting access to the `snap logs` command until a patch is available. As a temporary workaround, avoid using the `snap logs` command with unprivileged or unauthenticated users to minimize the risk of exploitation.