Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed by multiple parties because the action for a triggered rule can legitimately be an arbitrary operation as root. Thus, the software is behaving in accordance with its intended privilege model.
References
Configurations
No configuration.
History
28 Nov 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-266 |
28 Nov 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary operations as root. NOTE: this is disputed by multiple parties because the action for a triggered rule can legitimately be an arbitrary operation as root. Thus, the software is behaving in accordance with its intended privilege model. |
26 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-26 16:15
Updated : 2025-11-28 20:15
NVD link : CVE-2025-45311
Mitre link : CVE-2025-45311
CVE.ORG link : CVE-2025-45311
JSON object : View
Products Affected
No product.
CWE
CWE-266
Incorrect Privilege Assignment
