漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
himmelblaud-tasks: local privilege escalation via /tmp symlink attack on Kerberos ccache
Vulnerability Description
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as root, writes Kerberos cache files under /tmp/krb5cc_<uid> without symlink protections. Since commit 87a51ee, PrivateTmp is explicitly removed from the tasks daemon's systemd hardening, exposing it to the host /tmp. A local user can exploit this via symlink attacks to chown or overwrite arbitrary files, achieving local privilege escalation. This vulnerability is fixed in 3.1.0 and 2.3.8.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
Himmelblau 后置链接漏洞
Vulnerability Description
Himmelblau是Himmelblau开源的一个 Azure Entra ID 身份验证模块。 Himmelblau 3.1.0之前版本和2.3.8之前版本存在后置链接漏洞,该漏洞源于符号链接保护不足,可能导致本地权限提升。
CVSS Information
N/A
Vulnerability Type
N/A