PT-2024-15524 · Openssl+1 · Openssl+1
Will Dormann
·
Published
2024-04-03
·
Updated
2024-04-03
·
CVE-2024-0394
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rapid7 Minerva Armor versions prior to 4.5.5
Description
The issue is a privilege escalation vulnerability that allows an authenticated attacker to elevate privileges and execute arbitrary code with SYSTEM privilege. This is caused by the product's implementation of OpenSSL's
OPENSSLDIR parameter, which is set to a path accessible to low-privileged users.Recommendations
For versions prior to 4.5.5, update to version 4.5.5 to resolve the issue. As a temporary workaround, consider restricting access to the
OPENSSLDIR path to prevent low-privileged users from exploiting the vulnerability.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openssl
Rapid7 Minerva Armor