The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance (container) is launched with advanced capabilities (not launched as root)
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Link | Tags |
---|---|
https://github.com/Inist-CNRS/ezmaster/security/advisories/GHSA-g654-5qjf-g6cx | third party advisory |
https://github.com/Inist-CNRS/ezmaster/pull/51 | third party advisory patch |
https://github.com/Inist-CNRS/ezmaster/blob/master/CHANGELOG.md#ezmaster-5211 | third party advisory |