CVE-2024-39934

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" feature allows any user to edit any Python environment.
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://checkmk.com/werk/16434 - () https://checkmk.com/werk/16434 -
References () https://github.com/elabit/robotmk/commit/78c1174ab2df43813050d0c22e1efb8636f8715e - () https://github.com/elabit/robotmk/commit/78c1174ab2df43813050d0c22e1efb8636f8715e -
References () https://github.com/elabit/robotmk/compare/v2.0.0...v2.0.1 - () https://github.com/elabit/robotmk/compare/v2.0.0...v2.0.1 -
References () https://github.com/elabit/robotmk/releases/tag/v2.0.1 - () https://github.com/elabit/robotmk/releases/tag/v2.0.1 -

08 Jul 2024, 14:18

Type Values Removed Values Added
CWE CWE-284

05 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Robotmk anterior a 2.0.1 permite a un usuario local escalar privilegios (por ejemplo, a SYSTEM) si la configuración automatizada del entorno Python está habilitada, porque la función "uso de holoárbol compartido" permite a cualquier usuario editar cualquier entorno Python.

04 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-04 19:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39934

Mitre link : CVE-2024-39934

CVE.ORG link : CVE-2024-39934


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control