漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Exposed Session Token in canonical-livepatch client snap
Vulnerability Description
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems where an administrator has already enabled the Livepatch client with a valid Ubuntu Pro subscription. This token allows an attacker to access Livepatch services using the victim's credentials, as well as potentially cause issues to the Livepatch server.
CVSS Information
N/A
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Canonical Livepatch 安全漏洞
Vulnerability Description
Canonical Livepatch是Canonical开源的一个实现内核热修复更新与补丁管理的系统组件。 Canonical Livepatch 10.15.0之前版本存在安全漏洞,该漏洞源于访问控制不当,可能导致本地非特权用户通过向livepatchd.sock Unix域套接字发送未经身份验证的请求来获取敏感的身份验证令牌。
CVSS Information
N/A
Vulnerability Type
N/A