storaged-project CI status是storaged-project组织开源的一个存储管理守护进程。 storaged-project CI status 存在授权问题漏洞,该漏洞源于org.freedesktop.UDisks2.Filesystem.Mount() D-Bus方法中'as-user'选项的授权检查不足,可能允许具有活动控制台会话的本地攻击者伪造'as-user'参数,代表任意用户(包括特权账户)挂载文件系统,导致本地权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| None | None | 2.10.0< 2.11.2 |
affected |
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.11.0-2.el10_2.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:2.10.90-5.el10_0.3< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 2.10.0 ~ 2.11.2 | - |
|
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.11.0-2.el10_2.1 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:2.10.90-5.el10_0.3 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet