CVE-2024-5138
CVE-2024-5138 in github.com/snapcore/snapd
4.0
MEDIUM
CVSS 3.1
EPSS 0.83%
描述
The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.
如何修補 CVE-2024-5138
要修補 CVE-2024-5138,請將受影響套件升級到下列已修補版本。
- —升級至 2.63.1 或更新版本
CVE-2024-5138 正在被利用嗎?
低 — EPSS 為 0.8%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 2.51.6, < 2.63.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.0 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |