PT-2020-12220 · V2Ray · V2Rayl

Published

2020-03-15

·

Updated

2020-03-17

·

CVE-2020-10588

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions v2rayL version 2.1.3
Description The issue allows local users to achieve root access. This is because the scripts /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but are executed as root via Sudo.
Recommendations For v2rayL version 2.1.3, consider modifying the ownership or permissions of the /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh scripts to prevent low-privileged users from modifying them, or restrict the Sudo execution of these scripts to authorized users only.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10588

Affected Products

V2Rayl