Vulnerabilities
Vulnerable Software
Systemd Project:  >> Systemd  >> 241  Security Vulnerabilities
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker may use this flaw to access resources that will be owned by a potentially different service in the future, when the GID will be recycled.
CVSS Score
4.5
EPSS Score
0.002
Published
2019-04-26
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather than "allow_any".
CVSS Score
4.5
EPSS Score
0.001
Published
2019-04-09


Contact Us

Shodan ® - All rights reserved