1 results (0.001 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 1

23 Nov 2020 — Security Onion v2 prior to 2.3.10 has an incorrect sudo configuration, which allows the administrative user to obtain root access without using the sudo password by editing and executing /home/<user>/SecurityOnion/setup/so-setup. Security Onion versiones v2 anteriores a 2.3.10, presenta una configuración de sudo incorrecta, que permite al usuario administrador obtener acceso de root sin utilizar la contraseña de sudo editando y ejecutando /home/(user)/ SecurityOnion/setup/so-setup • https://github.com/Security-Onion-Solutions/securityonion/commit/b14670030349a2747a00ace665568ab5f51ac47b • CWE-306: Missing Authentication for Critical Function •