Security Advisory

CVE-2020-13695

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-06-01 17:45:16
Last updated 2024-08-04 12:25:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user has sudo privileges to execute grep as root without a password, which allows an attacker to obtain sensitive information via a grep of a /root/*.db or /etc/shadow file.