Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.
Link | Tags |
---|---|
https://huntr.com/bounties/21125f12-64a0-42a3-b218-26b9945a5bc0 | patch third party advisory exploit |
https://github.com/hestiacp/hestiacp/commit/acb766e1db53de70534524b3fbc2270689112630 | patch |