← Back

CVE-2022-3560

nvd nist
Published: Feb 2, 2023Modified: Mar 26, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.

Affected (6)

Pesign
1 product
Fedora
1 product
Enterprise Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 116
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 36
Version 37
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 7.0
Version 8.0
Version 9.0

References (2)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.