The www-data user can elevate its privileges because sudo...
High severity
Unreviewed
Published
Dec 11, 2024
to the GitHub Advisory Database
•
Updated Dec 12, 2024
Description
Published by the National Vulnerability Database
Dec 11, 2024
Published to the GitHub Advisory Database
Dec 11, 2024
Last updated
Dec 12, 2024
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.
References