Security Advisory

CVE-2019-19191

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-11-21 17:06:45
Last updated 2024-08-05 02:09:39
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.