7.8
CVSSv3

CVE-2020-36771

Published: 22/01/2024 Updated: 28/03/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

Vulnerable Product Search on Vulmon Subscribe to Product

cloudlinux cagefs

Exploits

CloudLinux CageFS versions 711-1 and below pass the authentication token as a command line argument In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user ...