CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2024-01-22T14:11:25.325Z
Updated: 2024-08-04T17:37:07.219Z
Reserved: 2024-01-22T13:33:26.500Z
Link: CVE-2020-36772
Vulnrichment
No data.
NVD
Status : Modified
Published: 2024-01-22T15:15:07.883
Modified: 2024-11-21T05:30:16.450
Link: CVE-2020-36772
Redhat
No data.