Unraid 6.8.0 allows authentication bypass.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Link | Tags |
---|---|
https://sysdream.com/news/lab/ | third party advisory |
https://forums.unraid.net/forum/7-announcements/ | release notes vendor advisory |
https://sysdream.com/news/lab/2020-02-06-cve-2020-5847-cve-2020-5849-unraid-6-8-0-unauthenticated-remote-code-execution-as-root/ | third party advisory exploit |
http://packetstormsecurity.com/files/157275/Unraid-6.8.0-Authentication-Bypass-Arbitrary-Code-Execution.html | exploit vdb entry third party advisory |