Description
CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.
Published: 2024-01-22
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-24212 CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.
History

Fri, 20 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cloudlinux Cagefs
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-06-20T18:33:37.646Z

Reserved: 2024-01-22T13:33:26.500Z

Link: CVE-2020-36771

cve-icon Vulnrichment

Updated: 2024-08-04T17:37:07.145Z

cve-icon NVD

Status : Modified

Published: 2024-01-22T14:15:07.530

Modified: 2025-06-20T19:15:20.827

Link: CVE-2020-36771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.