PT-2024-10823 · Cloudlinux · Cloudlinux Cagefs

David Lisa Gnedt

·

Published

2024-01-22

·

Updated

2024-03-28

·

CVE-2020-36771

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CloudLinux CageFS versions 7.1.1-1 and below
Description The issue allows local users to view the authentication token via the process list and gain code execution as another user, because the authentication token is passed as a command line argument. This can occur in certain configurations.
Recommendations For CloudLinux CageFS versions 7.1.1-1 and below, consider restricting access to the process list to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2020-36771

Affected Products

Cloudlinux Cagefs