Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
Link | Tags |
---|---|
https://huntr.dev/bounties/49e2cccc-bb56-4633-ba6a-b3803e251347 | issue tracking patch exploit third party advisory |
https://github.com/cockpit-hq/cockpit/commit/78d6ed3bf093ee11356ba66320c628c727068714 | patch |