跳转到帖子

CentOS Linux: CVE-2023-3899: Moderate: subscription-manager security update (CESA-2023:4701)

recommended_posts

发布于
  • Members

CentOS Linux: CVE-2023-3899: Moderate: subscription-manager security update (CESA-2023:4701)

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
08/23/2023
Created
08/29/2023
Added
08/29/2023
Modified
01/28/2025

Description

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.

Solution(s)

  • centos-upgrade-python-syspurpose
  • centos-upgrade-rhsm-gtk
  • centos-upgrade-subscription-manager
  • centos-upgrade-subscription-manager-cockpit
  • centos-upgrade-subscription-manager-debuginfo
  • centos-upgrade-subscription-manager-gui
  • centos-upgrade-subscription-manager-initial-setup-addon
  • centos-upgrade-subscription-manager-migration
  • centos-upgrade-subscription-manager-plugin-container
  • centos-upgrade-subscription-manager-plugin-ostree
  • centos-upgrade-subscription-manager-rhsm
  • centos-upgrade-subscription-manager-rhsm-certificates

References

  • CVE-2023-3899
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…