PT-2022-3531 · Apache · Apache Web Server
Anthony Candarini
+3
·
Published
2022-06-23
·
Updated
2022-07-06
·
CVE-2022-2104
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SEPCOS Single Package versions (affected versions not specified)
Description
The issue is related to insecure privilege management in the SEPCOS Single Package software. It allows a remote attacker to elevate their privileges. The
www-data account, used by the Apache web server, is configured to run sudo with no password for many commands, including /bin/sh and /bin/bash.Recommendations
For SEPCOS Single Package, restrict the use of the
sudo command for the www-data account to minimize the risk of exploitation.
As a temporary workaround, consider disabling the ability of the www-data account to run commands like /bin/sh and /bin/bash until a proper fix is applied.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Web Server