CVE-2021-3560

HIGH7.8⚠ KEVEPSS 9.1%

Red Hat Polkit Incorrect Authorization Vulnerability

發布日:2022/2/16修改日:2026/4/28加入 CISA KEV 日:2023/5/12

描述

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

參考連結(1)