PT-2020-12220 · V2Ray · V2Rayl
Published
2020-03-15
·
Updated
2020-03-17
·
CVE-2020-10588
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
v2rayL version 2.1.3
Description
The issue allows local users to achieve root access. This is because the scripts /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but are executed as root via Sudo.
Recommendations
For v2rayL version 2.1.3, consider modifying the ownership or permissions of the /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh scripts to prevent low-privileged users from modifying them, or restrict the Sudo execution of these scripts to authorized users only.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
V2Rayl