CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2024-01-22T13:53:35.745Z

Updated: 2024-03-28T18:25:31.741Z

Reserved: 2024-01-22T13:33:26.500Z


Link: CVE-2020-36771

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2024-01-22T14:15:07.530

Modified: 2024-03-28T19:15:46.773


Link: CVE-2020-36771

JSON object: View

cve-icon Redhat Information

No data.