Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-22809

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.432
EPSS Ranking 97.3%
CVSS Severity
CVSS v3 Score 7.8
References
Products affected by CVE-2023-22809
  • Sudo Project » Sudo » Version: 1.8.0
    cpe:2.3:a:sudo_project:sudo:1.8.0
  • Sudo Project » Sudo » Version: 1.8.1
    cpe:2.3:a:sudo_project:sudo:1.8.1
  • Sudo Project » Sudo » Version: 1.8.10
    cpe:2.3:a:sudo_project:sudo:1.8.10
  • Sudo Project » Sudo » Version: 1.8.11
    cpe:2.3:a:sudo_project:sudo:1.8.11
  • Sudo Project » Sudo » Version: 1.8.12
    cpe:2.3:a:sudo_project:sudo:1.8.12
  • Sudo Project » Sudo » Version: 1.8.13
    cpe:2.3:a:sudo_project:sudo:1.8.13
  • Sudo Project » Sudo » Version: 1.8.14
    cpe:2.3:a:sudo_project:sudo:1.8.14
  • Sudo Project » Sudo » Version: 1.8.15
    cpe:2.3:a:sudo_project:sudo:1.8.15
  • Sudo Project » Sudo » Version: 1.8.16
    cpe:2.3:a:sudo_project:sudo:1.8.16
  • Sudo Project » Sudo » Version: 1.8.17
    cpe:2.3:a:sudo_project:sudo:1.8.17
  • Sudo Project » Sudo » Version: 1.8.18
    cpe:2.3:a:sudo_project:sudo:1.8.18
  • Sudo Project » Sudo » Version: 1.8.19
    cpe:2.3:a:sudo_project:sudo:1.8.19
  • Sudo Project » Sudo » Version: 1.8.2
    cpe:2.3:a:sudo_project:sudo:1.8.2
  • Sudo Project » Sudo » Version: 1.8.20
    cpe:2.3:a:sudo_project:sudo:1.8.20
  • Sudo Project » Sudo » Version: 1.8.21
    cpe:2.3:a:sudo_project:sudo:1.8.21
  • Sudo Project » Sudo » Version: 1.8.22
    cpe:2.3:a:sudo_project:sudo:1.8.22
  • Sudo Project » Sudo » Version: 1.8.23
    cpe:2.3:a:sudo_project:sudo:1.8.23
  • Sudo Project » Sudo » Version: 1.8.24
    cpe:2.3:a:sudo_project:sudo:1.8.24
  • Sudo Project » Sudo » Version: 1.8.25
    cpe:2.3:a:sudo_project:sudo:1.8.25
  • Sudo Project » Sudo » Version: 1.8.26
    cpe:2.3:a:sudo_project:sudo:1.8.26
  • Sudo Project » Sudo » Version: 1.8.27
    cpe:2.3:a:sudo_project:sudo:1.8.27
  • Sudo Project » Sudo » Version: 1.8.28
    cpe:2.3:a:sudo_project:sudo:1.8.28
  • Sudo Project » Sudo » Version: 1.8.29
    cpe:2.3:a:sudo_project:sudo:1.8.29
  • Sudo Project » Sudo » Version: 1.8.3
    cpe:2.3:a:sudo_project:sudo:1.8.3
  • Sudo Project » Sudo » Version: 1.8.30
    cpe:2.3:a:sudo_project:sudo:1.8.30
  • Sudo Project » Sudo » Version: 1.8.31
    cpe:2.3:a:sudo_project:sudo:1.8.31
  • Sudo Project » Sudo » Version: 1.8.32
    cpe:2.3:a:sudo_project:sudo:1.8.32
  • Sudo Project » Sudo » Version: 1.8.4
    cpe:2.3:a:sudo_project:sudo:1.8.4
  • Sudo Project » Sudo » Version: 1.8.5
    cpe:2.3:a:sudo_project:sudo:1.8.5
  • Sudo Project » Sudo » Version: 1.8.6
    cpe:2.3:a:sudo_project:sudo:1.8.6
  • Sudo Project » Sudo » Version: 1.8.7
    cpe:2.3:a:sudo_project:sudo:1.8.7
  • Sudo Project » Sudo » Version: 1.8.8
    cpe:2.3:a:sudo_project:sudo:1.8.8
  • Sudo Project » Sudo » Version: 1.8.9
    cpe:2.3:a:sudo_project:sudo:1.8.9
  • Sudo Project » Sudo » Version: 1.9.0
    cpe:2.3:a:sudo_project:sudo:1.9.0
  • Sudo Project » Sudo » Version: 1.9.1
    cpe:2.3:a:sudo_project:sudo:1.9.1
  • Sudo Project » Sudo » Version: 1.9.10
    cpe:2.3:a:sudo_project:sudo:1.9.10
  • Sudo Project » Sudo » Version: 1.9.11
    cpe:2.3:a:sudo_project:sudo:1.9.11
  • Sudo Project » Sudo » Version: 1.9.12
    cpe:2.3:a:sudo_project:sudo:1.9.12
  • Sudo Project » Sudo » Version: 1.9.2
    cpe:2.3:a:sudo_project:sudo:1.9.2
  • Sudo Project » Sudo » Version: 1.9.3
    cpe:2.3:a:sudo_project:sudo:1.9.3
  • Sudo Project » Sudo » Version: 1.9.4
    cpe:2.3:a:sudo_project:sudo:1.9.4
  • Sudo Project » Sudo » Version: 1.9.5
    cpe:2.3:a:sudo_project:sudo:1.9.5
  • Sudo Project » Sudo » Version: 1.9.6
    cpe:2.3:a:sudo_project:sudo:1.9.6
  • Sudo Project » Sudo » Version: 1.9.7
    cpe:2.3:a:sudo_project:sudo:1.9.7
  • Sudo Project » Sudo » Version: 1.9.8
    cpe:2.3:a:sudo_project:sudo:1.9.8
  • Sudo Project » Sudo » Version: 1.9.9
    cpe:2.3:a:sudo_project:sudo:1.9.9
  • Apple » Macos » Version: N/A
    cpe:2.3:o:apple:macos:-
  • Apple » Macos » Version: 1.0
    cpe:2.3:o:apple:macos:1.0
  • Apple » Macos » Version: 10.15.7
    cpe:2.3:o:apple:macos:10.15.7
  • Apple » Macos » Version: 11.0
    cpe:2.3:o:apple:macos:11.0
  • Apple » Macos » Version: 11.0.1
    cpe:2.3:o:apple:macos:11.0.1
  • Apple » Macos » Version: 11.1
    cpe:2.3:o:apple:macos:11.1
  • Apple » Macos » Version: 11.1.0
    cpe:2.3:o:apple:macos:11.1.0
  • Apple » Macos » Version: 11.2
    cpe:2.3:o:apple:macos:11.2
  • Apple » Macos » Version: 11.2.1
    cpe:2.3:o:apple:macos:11.2.1
  • Apple » Macos » Version: 11.3
    cpe:2.3:o:apple:macos:11.3
  • Apple » Macos » Version: 11.3.1
    cpe:2.3:o:apple:macos:11.3.1
  • Apple » Macos » Version: 11.4
    cpe:2.3:o:apple:macos:11.4
  • Apple » Macos » Version: 11.5
    cpe:2.3:o:apple:macos:11.5
  • Apple » Macos » Version: 11.5.1
    cpe:2.3:o:apple:macos:11.5.1
  • Apple » Macos » Version: 11.6
    cpe:2.3:o:apple:macos:11.6
  • Apple » Macos » Version: 11.6.1
    cpe:2.3:o:apple:macos:11.6.1
  • Apple » Macos » Version: 11.6.2
    cpe:2.3:o:apple:macos:11.6.2
  • Apple » Macos » Version: 11.6.3
    cpe:2.3:o:apple:macos:11.6.3
  • Apple » Macos » Version: 11.6.5
    cpe:2.3:o:apple:macos:11.6.5
  • Apple » Macos » Version: 11.6.6
    cpe:2.3:o:apple:macos:11.6.6
  • Apple » Macos » Version: 11.6.7
    cpe:2.3:o:apple:macos:11.6.7
  • Apple » Macos » Version: 11.6.8
    cpe:2.3:o:apple:macos:11.6.8
  • Apple » Macos » Version: 11.7
    cpe:2.3:o:apple:macos:11.7
  • Apple » Macos » Version: 11.7.1
    cpe:2.3:o:apple:macos:11.7.1
  • Apple » Macos » Version: 11.7.10
    cpe:2.3:o:apple:macos:11.7.10
  • Apple » Macos » Version: 11.7.2
    cpe:2.3:o:apple:macos:11.7.2
  • Apple » Macos » Version: 11.7.3
    cpe:2.3:o:apple:macos:11.7.3
  • Apple » Macos » Version: 11.7.5
    cpe:2.3:o:apple:macos:11.7.5
  • Apple » Macos » Version: 11.7.6
    cpe:2.3:o:apple:macos:11.7.6
  • Apple » Macos » Version: 11.7.7
    cpe:2.3:o:apple:macos:11.7.7
  • Apple » Macos » Version: 11.7.8
    cpe:2.3:o:apple:macos:11.7.8
  • Apple » Macos » Version: 11.7.9
    cpe:2.3:o:apple:macos:11.7.9
  • Apple » Macos » Version: 12.0
    cpe:2.3:o:apple:macos:12.0
  • Apple » Macos » Version: 12.0.0
    cpe:2.3:o:apple:macos:12.0.0
  • Apple » Macos » Version: 12.0.1
    cpe:2.3:o:apple:macos:12.0.1
  • Apple » Macos » Version: 12.1
    cpe:2.3:o:apple:macos:12.1
  • Apple » Macos » Version: 12.2
    cpe:2.3:o:apple:macos:12.2
  • Apple » Macos » Version: 12.2.1
    cpe:2.3:o:apple:macos:12.2.1
  • Apple » Macos » Version: 12.3
    cpe:2.3:o:apple:macos:12.3
  • Apple » Macos » Version: 12.3.1
    cpe:2.3:o:apple:macos:12.3.1
  • Apple » Macos » Version: 12.4
    cpe:2.3:o:apple:macos:12.4
  • Apple » Macos » Version: 12.5
    cpe:2.3:o:apple:macos:12.5
  • Apple » Macos » Version: 12.5.1
    cpe:2.3:o:apple:macos:12.5.1
  • Apple » Macos » Version: 12.6
    cpe:2.3:o:apple:macos:12.6
  • Apple » Macos » Version: 12.6.1
    cpe:2.3:o:apple:macos:12.6.1
  • Apple » Macos » Version: 12.6.2
    cpe:2.3:o:apple:macos:12.6.2
  • Apple » Macos » Version: 12.6.3
    cpe:2.3:o:apple:macos:12.6.3
  • Apple » Macos » Version: 12.6.4
    cpe:2.3:o:apple:macos:12.6.4
  • Apple » Macos » Version: 12.6.5
    cpe:2.3:o:apple:macos:12.6.5
  • Apple » Macos » Version: 12.6.6
    cpe:2.3:o:apple:macos:12.6.6
  • Apple » Macos » Version: 12.6.7
    cpe:2.3:o:apple:macos:12.6.7
  • Apple » Macos » Version: 12.6.8
    cpe:2.3:o:apple:macos:12.6.8
  • Apple » Macos » Version: 12.6.9
    cpe:2.3:o:apple:macos:12.6.9
  • Apple » Macos » Version: 12.7
    cpe:2.3:o:apple:macos:12.7
  • Apple » Macos » Version: 12.7.1
    cpe:2.3:o:apple:macos:12.7.1
  • Apple » Macos » Version: 12.7.2
    cpe:2.3:o:apple:macos:12.7.2
  • Apple » Macos » Version: 12.7.3
    cpe:2.3:o:apple:macos:12.7.3
  • Apple » Macos » Version: 12.7.4
    cpe:2.3:o:apple:macos:12.7.4
  • Apple » Macos » Version: 12.7.5
    cpe:2.3:o:apple:macos:12.7.5
  • Apple » Macos » Version: 12.7.6
    cpe:2.3:o:apple:macos:12.7.6
  • Apple » Macos » Version: 13.0
    cpe:2.3:o:apple:macos:13.0
  • Apple » Macos » Version: 13.0.0
    cpe:2.3:o:apple:macos:13.0.0
  • Apple » Macos » Version: 13.0.1
    cpe:2.3:o:apple:macos:13.0.1
  • Apple » Macos » Version: 13.1
    cpe:2.3:o:apple:macos:13.1
  • Apple » Macos » Version: 13.2
    cpe:2.3:o:apple:macos:13.2
  • Apple » Macos » Version: 13.2.1
    cpe:2.3:o:apple:macos:13.2.1
  • Apple » Macos » Version: 13.3
    cpe:2.3:o:apple:macos:13.3
  • Apple » Macos » Version: 13.3.1
    cpe:2.3:o:apple:macos:13.3.1
  • Apple » Macos » Version: 13.3.3
    cpe:2.3:o:apple:macos:13.3.3
  • Apple » Macos » Version: 7.5.3
    cpe:2.3:o:apple:macos:7.5.3
  • Apple » Macos » Version: 7.6
    cpe:2.3:o:apple:macos:7.6
  • Apple » Macos » Version: 7.6.1
    cpe:2.3:o:apple:macos:7.6.1
  • Apple » Macos » Version: 8.0
    cpe:2.3:o:apple:macos:8.0
  • Apple » Macos » Version: 8.1
    cpe:2.3:o:apple:macos:8.1
  • Apple » Macos » Version: 8.5
    cpe:2.3:o:apple:macos:8.5
  • Apple » Macos » Version: 8.6
    cpe:2.3:o:apple:macos:8.6
  • Apple » Macos » Version: 9
    cpe:2.3:o:apple:macos:9
  • Apple » Macos » Version: 9.0
    cpe:2.3:o:apple:macos:9.0
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Fedoraproject » Fedora » Version: 36
    cpe:2.3:o:fedoraproject:fedora:36
  • Fedoraproject » Fedora » Version: 37
    cpe:2.3:o:fedoraproject:fedora:37


Contact Us

Shodan ® - All rights reserved