PT-2020-1558 · Apache+1 · Apache+1

Published

2020-01-06

·

Updated

2023-01-31

·

CVE-2019-19585

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rConfig version 3.9.3
Description An issue in rConfig allows an attacker to bypass local security restrictions due to insecure privilege management in the /etc/sudoers file. This occurs after an update to the rConfig specific Apache configuration, granting Apache high privileges for certain binaries.
Recommendations For rConfig version 3.9.3, consider restricting the privileges granted to Apache for specific binaries until a patch is available. As a temporary workaround, review and adjust the /etc/sudoers file to ensure that Apache's privileges are limited to necessary tasks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-00557
CVE-2019-19585

Affected Products

Apache
Rconfig