Skip to content

x/vulndb: potential Go vuln in github.com/snapcore/snapd: GHSA-jrr7-64m9-x984 #3395

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Closed
GoVulnBot opened this issue Jan 16, 2025 · 0 comments
Assignees
Labels
excluded: WITHDRAWN The source report was withdrawn before we published it in vulndb. triaged

Comments

@GoVulnBot
Copy link

Advisory GHSA-jrr7-64m9-x984 references a vulnerability in the following Go modules:

Module
github.com/snapcore/snapd

Description:

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-p9v8-q5m4-pf46. This link is maintained to preserve external references.

Original Description

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged u...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/snapcore/snapd
      non_go_versions:
        - introduced: 2.51.6
        - fixed: 2.63.1
      vulnerable_at: 0.0.0-20250116135323-846e5de90cba
summary: 'Duplicate Advisory: CVE-2024-5138: snapd snapctl auth bypass in github.com/snapcore/snapd'
ghsas:
    - GHSA-jrr7-64m9-x984
references:
    - advisory: https://github.com/advisories/GHSA-jrr7-64m9-x984
    - fix: https://github.com/snapcore/snapd/commit/68ee9c6aa916ab87dbfd9a26030690f2cabf1e14
    - web: https://bugs.launchpad.net/snapd/+bug/2065077
    - web: https://github.com/snapcore/snapd/security/advisories/GHSA-p9v8-q5m4-pf46
    - web: https://nvd.nist.gov/vuln/detail/CVE-2024-5138
    - web: https://www.cve.org/CVERecord?id=CVE-2024-5138
source:
    id: GHSA-jrr7-64m9-x984
    created: 2025-01-16T18:01:28.964363575Z
review_status: UNREVIEWED

@zpavlinovic zpavlinovic added triaged excluded: WITHDRAWN The source report was withdrawn before we published it in vulndb. and removed NeedsTriage labels Jan 16, 2025
@zpavlinovic zpavlinovic self-assigned this Jan 16, 2025
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
excluded: WITHDRAWN The source report was withdrawn before we published it in vulndb. triaged
Projects
None yet
Development

No branches or pull requests

2 participants