OpenZFS before 2.0.0-rc1, when used on FreeBSD, allows execute permissions for all directories.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://jira.ixsystems.com/browse/NAS-107270 | issue tracking patch exploit third party advisory |
https://github.com/openzfs/zfs/commit/716b53d0a14c72bda16c0872565dd1909757e73f | third party advisory patch |
https://reviews.freebsd.org/D26107 | issue tracking third party advisory patch |
https://github.com/openzfs/zfs/compare/zfs-0.8.4...zfs-2.0.0-rc1 | third party advisory release notes |