7.8
CVE-2021-25630
- EPSS 0.04%
- Veröffentlicht 23.02.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:55:10
- Quelle security@documentfoundation.or
- CVE-Watchlists
- Unerledigt
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing anything else "loolforkit" checks, if it was invoked by the "lool" user, and refuses to run with privileges, if it's not the case. In the vulnerable version of "loolforkit" this check was wrong, so a normal user could start "loolforkit" and eventually get local root privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Collaboraoffice ≫ Online Version >= 4.2.0 < 4.2.13
Collaboraoffice ≫ Online Version >= 6.4.0 < 6.4.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.086 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.