目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-22809— Sudo 安全漏洞

AI 预测 7.8 利用难度: 极易 EPSS 55.37% · P99

公开利用映射 2

ExploitDB · 1 EDB-51217 [local]
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2023-22809 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Sudo 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Sudo是一款使用于类Unix系统的,允许用户通过安全的方式使用特殊的权限执行命令的程序。 1.9.12p2 之前的 Sudo存在安全漏洞,该漏洞源于sudoedit(又名 -e)功能错误处理用户提供的环境变量(SUDO_EDITOR、VISUAL 和 EDITOR)中传递的额外参数,从而允许本地攻击者将任意条目附加到要处理的文件列表中 . 这可能导致特权升级。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
-n/a n/a -

二、漏洞 CVE-2023-22809 的公开POC

#POC 描述源链接神龙链接
1A script to automate privilege escalation with CVE-2023-22809 vulnerabilityhttps://github.com/n3m1dotsys/CVE-2023-22809-sudoedit-privescPOC详情
2Nonehttps://github.com/M4fiaB0y/CVE-2023-22809POC详情
3CVE-2023-22809 Linux Sudohttps://github.com/CKevens/CVE-2023-22809-sudo-POCPOC详情
4Nonehttps://github.com/hello4r1end/patch_CVE-2023-22809POC详情
5Analysis & Exploithttps://github.com/Chan9Yan9/CVE-2023-22809POC详情
6Nonehttps://github.com/pashayogi/CVE-2023-22809POC详情
7Nonehttps://github.com/asepsaepdin/CVE-2023-22809POC详情
8Running this exploit on a vulnerable system allows a local attacker to gain a root shell on the machine.https://github.com/Toothless5143/CVE-2023-22809POC详情
9A script to automate privilege escalation with CVE-2023-22809 vulnerabilityhttps://github.com/n3m1sys/CVE-2023-22809-sudoedit-privescPOC详情
10CVE-2023-22809 Linux Sudohttps://github.com/3yujw7njai/CVE-2023-22809-sudo-POCPOC详情
11Nonehttps://github.com/AntiVlad/CVE-2023-22809POC详情
12Sudo Privilege Escalation: CVE-2023-22809 Simulation This project simulates the Sudo privilege escalation vulnerability (CVE-2023-22809) to demonstrate how unauthorized root access can be gained. It involves identifying and exploiting this vulnerability in a controlled environment using Parrot OS, the Sudo command, and Bash scripting.https://github.com/laxmiyamkolu/SUDO-privilege-escalationPOC详情
13Nonehttps://github.com/D0rDa4aN919/CVE-2023-22809-ExploiterPOC详情
14CVE-2023-22809 Linux Sudohttps://github.com/AiK1d/CVE-2023-22809-sudo-POCPOC详情
15Nonehttps://github.com/Threekiii/Awesome-POC/blob/master/%E6%93%8D%E4%BD%9C%E7%B3%BB%E7%BB%9F%E6%BC%8F%E6%B4%9E/Linux%20sudo%20%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87%E6%BC%8F%E6%B4%9E%20CVE-2023-22809.mdPOC详情
16automatically exploit the sudoedit vulnerability fo CVE-2023-22809https://github.com/spidoman/CVE-2023-22809-automated-python-exploitsPOC详情
17Automates vulnerability check for sudo versions and privilege escalation via sudoedit if exploitable, helping users test and gain root access.https://github.com/Spydomain/CVE-2023-22809-automated-python-exploitsPOC详情
18CVE-2023-22809 Linux Sudohttps://github.com/P4x1s/CVE-2023-22809-sudo-POCPOC详情
19Implementation of the CVE-2023-22809https://github.com/ValeuDoamne/CVE-2023-22809POC详情
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2023-22809 的情报信息

登录查看更多情报信息。

CVE-2023-22809 厂商安全公告 (4)

CVE-2023-22809 公开利用代码 (3)

CVE-2023-22809 邮件列表归档 (5)

CVE-2023-22809 其他参考 (2)

同批安全公告 · n/a · 2023-01-18 · 共 22 条

CVE-2022-259015.3 MEDIUMCookieJar 安全漏洞
CVE-2022-45923OpenText Content Suite Platform 代码问题漏洞
CVE-2023-0164OrangeScrum 操作系统命令注入漏洞
CVE-2022-47966多款ZOHO ManageEngine产品安全漏洞
CVE-2022-47950OpenStack 安全漏洞
CVE-2022-47881Foxit PDF Reader 缓冲区错误漏洞
CVE-2022-46505MatrixSSL 安全漏洞
CVE-2022-45928OpenText Content Suite Platform 安全漏洞
CVE-2022-45927OpenText Content Suite Platform 安全漏洞
CVE-2022-45926OpenText Content Suite Platform 代码问题漏洞
CVE-2022-45925OpenText Content Suite Platform 安全漏洞
CVE-2022-45924OpenText Content Suite Platform 安全漏洞
CVE-2022-45922OpenText Content Suite Platform 安全漏洞
CVE-2022-45613Book Store Management System 跨站脚本漏洞
CVE-2022-4235RushBet 跨站脚本漏洞
CVE-2022-41417BlogEngine 输入验证错误漏洞
CVE-2022-3100OpenStack barbican 安全漏洞
CVE-2021-36630Ruckus Wireless SmartZone 安全漏洞
CVE-2021-33959Plex media server 访问控制错误漏洞
CVE-2020-35326inxedu SQL注入漏洞

显示前 20 条,共 22 条。 查看全部 → →

IV. Related Vulnerabilities

V. Comments for CVE-2023-22809

暂无评论


发表评论